389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for cve-2024-2199)
Published Sep 5, 2024
5.7
MEDIUMCVSS 3.1
EPSS 0.42%
Description
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
389-ds-base-0:1.3.11.1-7.el7_9
Fixed · RHSA-2024:7434
Red Hat Directory Server 11
redhat-ds:11/389-ds-base
Not affected
Red Hat Directory Server 12
redhat-ds:12/389-ds-base
Not affected
Red Hat Enterprise Linux 10
389-ds-base
Not affected
Red Hat Enterprise Linux 6
389-ds-base
Not affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Not affected
Red Hat Enterprise Linux 9
389-ds-base
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | 389-ds-base-0:1.3.11.1-7.el7_9 | Fixed | RHSA-2024:7434 |
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Not affected | n/a |
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 10 | 389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 6 | 389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 9 | 389-ds-base | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/errata/RHSA-2024:7434 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-8445 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2310110 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2025/01/msg00015.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-8445
- https://www.cve.org/CVERecord?id=CVE-2024-8445
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:7434 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-8445 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2310110 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://lists.debian.org/debian-lts-announce/2025/01/msg00015.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-8445 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-8445 |
Change history (0)
No recorded changes yet.