All errata/sisyphus_riscv64/ALT-PU-2024-1201-1
ALT-PU-2024-1201-1

Package update 389-ds-base in branch sisyphus_riscv64

Version2.4.4-alt1
Task#0
Published2024-01-16
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2023-04786
MEDIUM6.5

Уязвимость плагина Content Synchronization сервера службы каталогов 389 Directory Server, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2023-08-21Modified: 2024-09-24
CVSS 3.xMEDIUM 6.5
CVSS:3.x/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:C
References
CVE-2022-2850
MEDIUM6.5

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

Published: 2022-10-14Modified: 2025-11-03
CVSS 3.xMEDIUM 6.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H