Bug 1436575 (CVE-2017-2668) - CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
Summary: CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2017-2668
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1437005 1437006 1437776 1437777 1440613
Blocks: 1436583
TreeView+ depends on / blocked
 
Reported: 2017-03-28 08:44 UTC by Adam Mariš
Modified: 2021-02-17 02:24 UTC (History)
9 users (show)

Fixed In Version: 389-ds-base 1.3.5.17, 389-ds-base 1.3.6.10
Doc Type: If docs needed, set a value
Doc Text:
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Clone Of:
Environment:
Last Closed: 2017-04-12 20:11:01 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github 389ds 389-ds-base issues 2279 0 None None None 2020-09-13 21:58:44 UTC
Red Hat Product Errata RHSA-2017:0893 0 normal SHIPPED_LIVE Important: 389-ds-base security and bug fix update 2017-04-11 15:46:58 UTC
Red Hat Product Errata RHSA-2017:0920 0 normal SHIPPED_LIVE Important: 389-ds-base security and bug fix update 2017-04-12 16:27:01 UTC

Description Adam Mariš 2017-03-28 08:44:56 UTC
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

Comment 1 Adam Mariš 2017-03-28 08:45:00 UTC
Acknowledgments:

Name: Joachim Jabs (F24)

Comment 9 Dhiru Kholia 2017-04-10 05:50:11 UTC
Created 389-ds-base tracking bugs for this issue:

Affects: fedora-all [bug 1440613]

Comment 10 errata-xmlrpc 2017-04-11 11:49:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:0893 https://access.redhat.com/errata/RHSA-2017:0893

Comment 11 errata-xmlrpc 2017-04-12 12:36:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0920 https://access.redhat.com/errata/RHSA-2017:0920

Comment 12 mreynolds 2017-04-18 18:22:23 UTC
For tracking:

upstream ticket

https://pagure.io/389-ds-base/issue/49220


Note You need to log in before you can comment on or make changes to this bug.