5.5

CVE-2024-1062

389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ 389 Directory Server Version < 2.2.0
Redhat ≫ Directory Server Version -
Redhat ≫ Directory Server Version 11.7
Redhat ≫ Directory Server Version 11.8
Fedoraproject ≫ Fedora Version 39
Fedoraproject ≫ Fedora Version 40
Fedoraproject ≫ Fedora Version 41
Redhat ≫ Directory Server Version 12.0
   Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Enterprise Linux Eus Version 9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.234
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

https://access.redhat.com/errata/RHSA-2024:1074
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1372
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3047
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:4209
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:4633
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:5690
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:7458
Vendor Advisory
https://access.redhat.com/errata/RHSA-2025:1632
https://access.redhat.com/security/cve/CVE-2024-1062
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2256711
Vendor Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2261879
Vendor Advisory
Issue Tracking