Bug 1436575 (CVE-2017-2668)

Summary: CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dkholia, lkrispen, mreynolds, nhosoi, nkinder, rmeggins, security-response-team, tbordaz, wibrown
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,public=20170410,reported=20170327,source=researcher,cvss3=6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H,cwe=CWE-119,rhel-6/389-ds-base=affected,rhel-7/389-ds-base=affected,fedora-all/389-ds-base=affected
Fixed In Version: 389-ds-base 1.3.5.17, 389-ds-base 1.3.6.10 Doc Type: If docs needed, set a value
Doc Text:
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-04-12 20:11:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1437005, 1437006, 1437776, 1437777, 1440613    
Bug Blocks: 1436583    

Description Adam Mariš 2017-03-28 08:44:56 UTC
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

Comment 1 Adam Mariš 2017-03-28 08:45:00 UTC
Acknowledgments:

Name: Joachim Jabs (F24)

Comment 9 Dhiru Kholia 2017-04-10 05:50:11 UTC
Created 389-ds-base tracking bugs for this issue:

Affects: fedora-all [bug 1440613]

Comment 10 errata-xmlrpc 2017-04-11 11:49:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:0893 https://access.redhat.com/errata/RHSA-2017:0893

Comment 11 errata-xmlrpc 2017-04-12 12:36:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0920 https://access.redhat.com/errata/RHSA-2017:0920

Comment 12 mreynolds 2017-04-18 18:22:23 UTC
For tracking:

upstream ticket

https://pagure.io/389-ds-base/issue/49220