Redhat

Directory Server

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 01.10.2026 23:27:47
  • Zuletzt bearbeitet 07.10.2026 21:17:20

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade an...

  • EPSS 0.48%
  • Veröffentlicht 07.09.2026 14:14:58
  • Zuletzt bearbeitet 08.09.2026 20:17:29

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges t...

  • EPSS 0.56%
  • Veröffentlicht 07.09.2026 14:14:53
  • Zuletzt bearbeitet 08.09.2026 19:08:15

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bin...

  • EPSS 0.84%
  • Veröffentlicht 07.09.2026 14:14:43
  • Zuletzt bearbeitet 08.09.2026 22:17:40

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) prod...

  • EPSS 0.42%
  • Veröffentlicht 10.08.2026 09:38:10
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 14:55:33
  • Zuletzt bearbeitet 09.08.2026 13:54:50

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as fai...

  • EPSS 0.69%
  • Veröffentlicht 31.07.2026 09:18:58
  • Zuletzt bearbeitet 18.08.2026 15:16:48

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated repl...

  • EPSS 0.87%
  • Veröffentlicht 31.07.2026 09:18:50
  • Zuletzt bearbeitet 18.08.2026 15:16:49

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checkin...

  • EPSS 0.4%
  • Veröffentlicht 22.07.2026 12:51:43
  • Zuletzt bearbeitet 22.07.2026 19:16:57

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an ...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 10:15:30
  • Zuletzt bearbeitet 09.07.2026 19:36:15

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurement...