Fedora Account System
Red Hat Associate
Red Hat Customer
The 389 Directory Server has a memory exhaustion vulnerability in ns-slapd due to the lack of attribute length restrictions. A remote authenticated attacker could exploit this via an attribute like 'gecos' to upload data of arbitrary size and cause a denial of service.
Need to confirm the affected component and that this is a separate issue to CVE-2018-1089 before assigning a CVE.
Unable to reproduce on 389-ds-base-1.2.11.15-95 RHEL6 32bit or 1.3.7.5 on RHEL7. Waiting on response from reporter. Will re-open and re-investigate if new information comes to light.