Debian 389-Ds-Base vulnerabilities
48 known vulnerabilities affecting debian/389-ds-base.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM27LOW3
Vulnerabilities
Page 3 of 3
CVE-2025-2487P4MEDIUMCVSS 4.9fixed in 389-ds-base 3.1.2+dfsg1-1 (sid)2025
CVE-2025-2487 [MEDIUM] CVE-2025-2487: 389-ds-base - A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing ...
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.
Scope: loc
debian
CVE-2024-5953P4MEDIUMCVSS 5.7fixed in 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm)2024
CVE-2024-5953 [MEDIUM] CVE-2024-5953: 389-ds-base - A denial of service vulnerability was found in the 389-ds-base LDAP server. This...
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
Scope: local
bookworm: resolved (fixed in 2.3.1+dfsg1-1+deb12u1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (
debian
CVE-2013-0312P4MEDIUMCVSS 5.0fixed in 389-ds-base 1.3.0.3-1 (bookworm)2013
CVE-2013-0312 [MEDIUM] CVE-2013-0312: 389-ds-base - 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of...
389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.
Scope: local
bookworm: resolved (fixed in 1.3.0.3-1)
bullseye: resolved (fixed in 1.3.0.3-1)
sid: resolved (fixed in 1.3.0.3-1)
trixie: resolved (fixed in 1.3.0.3-1)
debian
CVE-2013-2219P4MEDIUMCVSS 4.0fixed in 389-ds-base 1.3.2.9-1 (bookworm)2013
CVE-2013-2219 [MEDIUM] CVE-2013-2219: 389-ds-base - The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not pr...
The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.
Scope: local
bookworm: resolved (fixed in 1.3.2.9-1)
bullseye: resolved (fixed in 1.3.2.9-1)
sid: resolved (fixed in 1.3.2.9-1)
t
debian
CVE-2019-10224P4MEDIUMCVSS 4.6fixed in 389-ds-base 1.4.1.5-1 (bookworm)2019
CVE-2019-10224 [MEDIUM] CVE-2019-10224: 389-ds-base - A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When execu...
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Scope: local
bookwor
debian
CVE-2014-8112P4MEDIUMCVSS 4.0fixed in 389-ds-base 1.3.3.5-4 (bookworm)2014
CVE-2014-8112 [MEDIUM] CVE-2014-8112: 389-ds-base - 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3....
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Scope: local
bookworm: resolved (fixed in 1.3.3.5-4)
bullseye: resolved (fixed in 1.3.3.5-4)
debian
CVE-2013-4485P4MEDIUMCVSS 4.0fixed in 389-ds-base 1.3.2.9-1 (bookworm)2013
CVE-2013-4485 [MEDIUM] CVE-2013-4485: 389-ds-base - 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) a...
389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.
Scope: local
bookworm: resolved (fixed in 1.3.2.9-1)
bullseye: resolved (fixed in 1.3.2.9-1)
sid: resolved (fixed in 1.3.2.9-1)
trixie: resolve
debian
CVE-2013-1897P4LOWCVSS 2.6fixed in 389-ds-base 1.3.2.9-1 (bookworm)2013
CVE-2013-1897 [LOW] CVE-2013-1897: 389-ds-base - The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1....
The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via
debian
← Previous3 / 3