CVE-2024-3657
published 2024-05-28CVE-2024-3657: A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.26%
66.4th percentile
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm) | 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm) |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| port389 | 389-ds-base | >= 0 < 2.3.1+dfsg1-1+deb12u1 | 2.3.1+dfsg1-1+deb12u1 |
| port389 | 389-ds-base | >= 0 < 3.1.1+dfsg1-1 | 3.1.1+dfsg1-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
vendor_redhat·2024-05-28·CVSS 7.5
CVE-2024-3657 [HIGH] CWE-20 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
Statement: This vulnerability is categorized as an important severity issue rather than a critical one because, while it can cause a denial of service by stopping the directory service, it does not allow for remote code execution, privilege escalation, or data exfiltration. The impact is limited to service disruption, which can be mitigated by monitoring and automatic service restarts. Additionally, exp
Debian
CVE-2024-3657: 389-ds-base - A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially ...
vendor_debian·2024·CVSS 7.5
CVE-2024-3657 [HIGH] CVE-2024-3657: 389-ds-base - A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially ...
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
Scope: local
bookworm: resolved (fixed in 2.3.1+dfsg1-1+deb12u1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 3.1.1+dfsg1-1)
trixie: resolved (fixed in 3.1.1+dfsg1-1)
OSV
CVE-2024-3657: A flaw was found in 389-ds-base
osv·2024-05-28·CVSS 7.5
CVE-2024-3657 [HIGH] CVE-2024-3657: A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:3591https://access.redhat.com/errata/RHSA-2024:3837https://access.redhat.com/errata/RHSA-2024:4092https://access.redhat.com/errata/RHSA-2024:4209https://access.redhat.com/errata/RHSA-2024:4210https://access.redhat.com/errata/RHSA-2024:4235https://access.redhat.com/errata/RHSA-2024:4633https://access.redhat.com/errata/RHSA-2024:5690https://access.redhat.com/errata/RHSA-2024:6576https://access.redhat.com/errata/RHSA-2024:7458https://access.redhat.com/errata/RHSA-2025:1632https://access.redhat.com/security/cve/CVE-2024-3657https://bugzilla.redhat.com/show_bug.cgi?id=2274401https://access.redhat.com/errata/RHSA-2024:3591https://access.redhat.com/errata/RHSA-2024:3837https://access.redhat.com/errata/RHSA-2024:4092https://access.redhat.com/errata/RHSA-2024:4209https://access.redhat.com/errata/RHSA-2024:4210https://access.redhat.com/errata/RHSA-2024:4235https://access.redhat.com/errata/RHSA-2024:4633https://access.redhat.com/security/cve/CVE-2024-3657https://bugzilla.redhat.com/show_bug.cgi?id=2274401https://lists.debian.org/debian-lts-announce/2025/01/msg00015.html
2024-05-28
Published