Back

MEDIUM

389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c

Published May 28, 2024

Description

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

LDAP servers are not usually exposed to the open internet, requiring adjacent connectivity for a successful attack. This issue also requires a compromised user account to perform the attack. Therefore, this flaw is rated as a Moderate severity.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 28, 2024
Updated Jun 26, 2026
Reserved Mar 5, 2024
CISA Vulnrichment
Updated May 28, 2024
NVD
Status Deferred
Modified Jun 26, 2026
Red Hat
Severity Moderate
Public date May 28, 2024