Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1619450 - (CVE-2018-14624) CVE-2018-14624 389-ds-base: Server crash through modify command with large DN
CVE-2018-14624 389-ds-base: Server crash through modify command with large DN
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180831:0036,...
: Security
: 1621942 (view as bug list)
Depends On: 1624196 1624198 1614820 1623247 1623721
Blocks: 1619452 1621943
  Show dependency treegraph
 
Reported: 2018-08-20 17:13 EDT by Pedro Sampaio
Modified: 2018-10-18 14:07 EDT (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was discovered in 389-ds-base. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-10-18 14:07:35 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
patch for crash in vslapd_log_emergency_error (3.70 KB, patch)
2018-09-04 00:30 EDT, Doran Moppert
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2757 None None None 2018-09-25 15:06 EDT

  None (edit)
Description Pedro Sampaio 2018-08-20 17:13:03 EDT
A flaw was found in 389-ds-base. The server can be crashed by an anonymous client through a ldapmodify command with a large DN argument potentially causing denial of service.

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1614820
Comment 1 Sam Fowler 2018-08-26 20:15:30 EDT
*** Bug 1621942 has been marked as a duplicate of this bug. ***
Comment 8 Doran Moppert 2018-08-30 20:40:54 EDT
Created 389-ds-base tracking bugs for this issue:

Affects: fedora-all [bug 1624198]
Comment 9 Salvatore Bonaccorso 2018-09-01 16:38:43 EDT
Hi

Since https://bugzilla.redhat.com/show_bug.cgi?id=1621942 is not accessible/restricted, could you share more information on this issue? (CVE-2018-14624). Which upstream versions are affected, and is there a fix for the issue?

Regards,
Salvatore
Comment 10 Doran Moppert 2018-09-04 00:30 EDT
Created attachment 1480666 [details]
patch for crash in vslapd_log_emergency_error

Adding patch here since it hasn't made its way upstream yet.
Comment 13 Salvatore Bonaccorso 2018-09-07 16:22:42 EDT
Doran and Sam: thank you
Comment 14 errata-xmlrpc 2018-09-25 15:05:59 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:2757 https://access.redhat.com/errata/RHSA-2018:2757

Note You need to log in before you can comment on or make changes to this bug.