CVE-2024-8445
published 2024-09-05CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash…
PriorityP422medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
EPSS
0.42%
34.4th percentile
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 2.0.11-1 (bookworm) | 389-ds-base 2.0.11-1 (bookworm) |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| port389 | 389-ds-base | >= 0 < 2.0.11-1 | 2.0.11-1 |
| port389 | 389-ds-base | >= 0 < 2.0.11-1 | 2.0.11-1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q6m-vr5h-rqq5: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
ghsa_unreviewed·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CWE-20 GHSA-9q6m-vr5h-rqq5: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
OSV
CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
osv·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Red Hat
389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
vendor_redhat·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CWE-20 389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: red
Debian
CVE-2024-8445: 389-ds-base - The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios...
vendor_debian·2024·CVSS 5.7
CVE-2024-8445 [MEDIUM] CVE-2024-8445: 389-ds-base - The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios...
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Scope: local
bookworm: resolved (fixed in 2.0.11-1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 2.0.11-1)
trixie: resolved (fixed in 2.0.11-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-05
Published