389-ds-base: malformed userpassword may cause crash at do_modify in slapd/modify.c
Published May 28, 2024
5.7
MEDIUMCVSS 3.1
EPSS 0.56%
Description
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
Affected products
No data.
No data.
No data.
Red Hat Directory Server 11.5 E4S for RHEL 8
redhat-ds:11-8060020250210084424.0ca98e7e
Fixed · RHSA-2025:1632
Red Hat Directory Server 11.8 for RHEL 8
redhat-ds:11-8090020240606122459.91529cd0
Fixed · RHSA-2024:4209
Red Hat Directory Server 11.9 for RHEL 8
redhat-ds:11-8100020240604161237.37ed7c03
Fixed · RHSA-2024:4210
Red Hat Directory Server 12.4 for RHEL 9
redhat-ds:12-9040020240604143706.1674d574
Fixed · RHSA-2024:4092
Red Hat Enterprise Linux 7
389-ds-base-0:1.3.11.1-5.el7_9
Fixed · RHSA-2024:3591
Red Hat Enterprise Linux 8
389-ds:1.4-8100020240613122040.25e700aa
Fixed · RHSA-2024:4235
Red Hat Enterprise Linux 8.8 Extended Update Support
389-ds:1.4-8080020240807050952.6dbb3803
Fixed · RHSA-2024:5690
Red Hat Enterprise Linux 9
389-ds-base-0:2.4.5-8.el9_4
Fixed · RHSA-2024:3837
Red Hat Enterprise Linux 9.2 Extended Update Support
389-ds-base-0:2.2.4-9.el9_2
Fixed · RHSA-2024:4633
Red Hat Enterprise Linux 6
389-ds-base
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Directory Server 11.5 E4S for RHEL 8 | redhat-ds:11-8060020250210084424.0ca98e7e | Fixed | RHSA-2025:1632 |
| Red Hat Directory Server 11.8 for RHEL 8 | redhat-ds:11-8090020240606122459.91529cd0 | Fixed | RHSA-2024:4209 |
| Red Hat Directory Server 11.9 for RHEL 8 | redhat-ds:11-8100020240604161237.37ed7c03 | Fixed | RHSA-2024:4210 |
| Red Hat Directory Server 12.4 for RHEL 9 | redhat-ds:12-9040020240604143706.1674d574 | Fixed | RHSA-2024:4092 |
| Red Hat Enterprise Linux 7 | 389-ds-base-0:1.3.11.1-5.el7_9 | Fixed | RHSA-2024:3591 |
| Red Hat Enterprise Linux 8 | 389-ds:1.4-8100020240613122040.25e700aa | Fixed | RHSA-2024:4235 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | 389-ds:1.4-8080020240807050952.6dbb3803 | Fixed | RHSA-2024:5690 |
| Red Hat Enterprise Linux 9 | 389-ds-base-0:2.4.5-8.el9_4 | Fixed | RHSA-2024:3837 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | 389-ds-base-0:2.2.4-9.el9_2 | Fixed | RHSA-2024:4633 |
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
LDAP servers are not usually exposed to the open internet, requiring adjacent connectivity for a successful attack. This issue also requires a compromised user account to perform the attack. Therefore, this flaw is rated as a Moderate severity.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 28, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.56% (0.00565) | 44.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.53% (0.00533) | 40.53th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.51% (0.00507) | 64.19th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.00th | v3 (v2023.03.01) |
| Jul 3, 2024 | 0.04% (0.00044) | 13.23th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.04% (0.00045) | 15.43th | v3 (v2023.03.01) |
| May 29, 2024 | 0.04% (0.00043) | 8.72th | v3 (v2023.03.01) |
References (15)
- https://access.redhat.com/errata/RHSA-2024:3591 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3837 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4092 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4209 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4210 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4235 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4633 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:5690 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:1632 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-2199 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2267976 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2025/01/msg00015.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-2199
- https://www.cve.org/CVERecord?id=CVE-2024-2199
- https://www.port389.org/docs/389ds/releases/release-3-1-1.html
Change history (0)
No recorded changes yet.