cbcvebase.

Debian 389-Ds-Base vulnerabilities

48 known vulnerabilities affecting debian/389-ds-base.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM27LOW3

Vulnerabilities

Page 2 of 3
CVE-2018-14638P3HIGHCVSS 7.5fixed in 389-ds-base 1.4.0.18-1 (bookworm)2018
CVE-2018-14638 [HIGH] CVE-2018-14638: 389-ds-base - A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd ... A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. Scope: local bookworm: resolved (fixed in 1.4.0.18-1) bullseye: resolved (fixed in 1.4.0.18-1) sid: resolved (fixed in 1.4.0.18-1) trixie: resol
debian
CVE-2018-14624P3HIGHCVSS 7.5fixed in 389-ds-base 1.4.0.18-1 (bookworm)2018
CVE-2018-14624 [HIGH] CVE-2018-14624: 389-ds-base - A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8... A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash. Scope: local bookworm: resolved (fixed in 1.4.0.18-1)
debian
CVE-2016-0741P3HIGHCVSS 7.5fixed in 389-ds-base 1.3.4.8-1 (bookworm)2016
CVE-2016-0741 [HIGH] CVE-2016-0741: 389-ds-base - slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.... slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection. Scope: local bookworm: resolved (fixed in 1.3.4.8-1) bullseye: resolved (fixed in 1.3.4.8-1) sid: resolved (fixed in 1.3.4.8-
debian
CVE-2019-14824P3MEDIUMCVSS 6.5fixed in 389-ds-base 1.4.2.4-1 (bookworm)2019
CVE-2019-14824 [MEDIUM] CVE-2019-14824: 389-ds-base - A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'se... A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes. Scope: local bookworm: resolved (fixed in 1.4.2.4-1) bullseye: resolved (fixed in 1.4.2.4-1) sid: resolved (fixed in
debian
CVE-2021-3514P4MEDIUMCVSS 6.5fixed in 389-ds-base 1.4.4.11-2 (bookworm)2021
CVE-2021-3514 [MEDIUM] CVE-2021-3514: 389-ds-base - When using a sync_repl client in 389-ds-base, an authenticated attacker can caus... When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. Scope: local bookworm: resolved (fixed in 1.4.4.11-2) bullseye: resolved (fixed in 1.4.4.11-2) sid: resolved (fixed in 1.4.4.11-2) trixie: resolved (fixed in 1.4.4.11-2)
debian
CVE-2024-6237P4MEDIUMCVSS 6.5fixed in 389-ds-base 2.4.5+dfsg1-1 (sid)2024
CVE-2024-6237 [MEDIUM] CVE-2024-6237: 389-ds-base - A flaw was found in the 389 Directory Server. This flaw allows an unauthenticate... A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. Scope: local bookworm: open bullseye: open sid: resolved (fixed in 2.4.5+dfsg1-1) trixie: resolved (fixed in 2.4.5+dfsg1-1)
debian
CVE-2020-35518P4MEDIUMCVSS 5.3fixed in 389-ds-base 1.4.4.10-1 (bookworm)2020
CVE-2020-35518 [MEDIUM] CVE-2020-35518: 389-ds-base - When binding against a DN during authentication, the reply from 389-ds-base will... When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database. Scope: local bookworm: resolved (fixed in 1.4.4.10-1) bullseye: resolved (fixed in 1.4.4.10-1) sid: resolved (fixed in 1.4.4.10-1) tr
debian
CVE-2017-2668P4MEDIUMCVSS 6.5fixed in 389-ds-base 1.3.5.17-1 (bookworm)2017
CVE-2017-2668 [MEDIUM] CVE-2017-2668: 389-ds-base - 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid po... 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service. Scope: local bookworm: resolved (fixed in 1.3.5.17-1) bullseye: resolve
debian
CVE-2012-4450P4MEDIUMCVSS 6.0fixed in 389-ds-base 1.2.11.15-1 (bookworm)2012
CVE-2012-4450 [MEDIUM] CVE-2012-4450: 389-ds-base - 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is ... 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry. Scope: local bookworm: resolved (fixed in 1.2.11.15-1) bullseye: resolved (fixed in 1.2.11.15-1) sid: resolved (fixed in 1.2.11.15-1) trix
debian
CVE-2018-10935P4MEDIUMCVSS 6.5fixed in 389-ds-base 1.4.0.15-1 (bookworm)2018
CVE-2018-10935 [MEDIUM] CVE-2018-10935: 389-ds-base - A flaw was found in the 389 Directory Server that allows users to cause a crash ... A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort. Scope: local bookworm: resolved (fixed in 1.4.0.15-1) bullseye: resolved (fixed in 1.4.0.15-1) sid: resolved (fixed in 1.4.0.15-1) trixie: resolved (fixed in 1.4.0.15-1)
debian
CVE-2022-2850P4MEDIUMCVSS 6.5fixed in 389-ds-base 2.3.1-1 (bookworm)2022
CVE-2022-2850 [MEDIUM] CVE-2022-2850: 389-ds-base - A flaw was found In 389-ds-base. When the Content Synchronization plugin is enab... A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. Scope: local bookworm: resolved (fixed in 2.3.1-1
debian
CVE-2018-10850P4MEDIUMCVSS 5.9fixed in 389-ds-base 1.4.0.15-1 (bookworm)2018
CVE-2018-10850 [MEDIUM] CVE-2018-10850: 389-ds-base - 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition ... 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service. Scope: local bookworm: resolved (fixed in 1.4.0.15-1) bullseye: resolved (fixed in 1.4.0.15-1) sid: resolved
debian
CVE-2014-3562P4MEDIUMCVSS 5.0fixed in 389-ds-base 1.3.2.21-1 (bookworm)2014
CVE-2014-3562 [MEDIUM] CVE-2014-3562: 389-ds-base - Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, ... Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. Scope: local bookworm: resolved (fixed in 1.3.2.21-1) bullseye: resolved (fixed in 1.3.2.21-1) sid: resolved (fixed in 1.3.2.21-1) trixie: resolved (fixed in 1.3.2.21-1)
debian
CVE-2014-8105P4MEDIUMCVSS 5.0fixed in 389-ds-base 1.3.3.5-4 (bookworm)2014
CVE-2014-8105 [MEDIUM] CVE-2014-8105: 389-ds-base - 389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properl... 389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.3.3.5-4) bullseye: resolved (fixed in 1.3.3.5-4) sid: resolved (fixed in 1.3.3.
debian
CVE-2023-1055P4MEDIUMCVSS 5.5fixed in 389-ds-base 2.3.4+dfsg1-1 (sid)2023
CVE-2023-1055 [MEDIUM] CVE-2023-1055: 389-ds-base - A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to de... A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vuln
debian
CVE-2013-0336P4MEDIUMCVSS 5.0fixed in 389-ds-base 1.3.2.9-1 (bookworm)2013
CVE-2013-0336 [MEDIUM] CVE-2013-0336: 389-ds-base - The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_ex... The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server. Scope: local bookworm: resolved (fixed in 1.3.2.9-1) bullseye: resolved (fi
debian
CVE-2013-4283P4MEDIUMCVSS 5.0fixed in 389-ds-base 1.3.2.9-1 (bookworm)2013
CVE-2013-4283 [MEDIUM] CVE-2013-4283: 389-ds-base - ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause... ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request. Scope: local bookworm: resolved (fixed in 1.3.2.9-1) bullseye: resolved (fixed in 1.3.2.9-1) sid: resolved (fixed in 1.3.2.9-1) trixie: resolved (fixed in 1.3.2.9-1)
debian
CVE-2024-8445P4MEDIUMCVSS 5.7fixed in 389-ds-base 2.0.11-1 (bookworm)2024
CVE-2024-8445 [MEDIUM] CVE-2024-8445: 389-ds-base - The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios... The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input. Scope: local bookworm: resolved (fixed in 2.0.11-1) bullseye: resolved (fixed in 1.4.4.11-2+deb11u1) sid: resolved (fixed in 2.0.11-1) trixie: resolved
debian
CVE-2024-1062P4MEDIUMCVSS 5.5fixed in 389-ds-base 2.3.4+dfsg1-1 (sid)2024
CVE-2024-1062 [MEDIUM] CVE-2024-1062: 389-ds-base - A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of s... A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. Scope: local bookworm: open bullseye: open sid: resolved (fixed in 2.3.4+dfsg1-1) trixie: resolved (fixed in 2.3.4+dfsg1-1)
debian
CVE-2024-2199P4MEDIUMCVSS 5.7fixed in 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm)2024
CVE-2024-2199 [MEDIUM] CVE-2024-2199: 389-ds-base - A denial of service vulnerability was found in 389-ds-base ldap server. This iss... A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. Scope: local bookworm: resolved (fixed in 2.3.1+dfsg1-1+deb12u1) bullseye: resolved (fixed in 1.4.4.11-2+deb11u1) sid: resolved (fixed in 3.1.1+dfsg1-1) trixie: resolved (
debian
Debian 389-Ds-Base vulnerabilities | cvebase