Redhat

Directory Server

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 10.08.2026 09:38:10
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access...

  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 14:55:33
  • Zuletzt bearbeitet 09.08.2026 13:54:50

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as fai...

  • EPSS 0.69%
  • Veröffentlicht 31.07.2026 09:18:58
  • Zuletzt bearbeitet 18.08.2026 15:16:48

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated repl...

  • EPSS 0.87%
  • Veröffentlicht 31.07.2026 09:18:50
  • Zuletzt bearbeitet 18.08.2026 15:16:49

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checkin...

  • EPSS 0.4%
  • Veröffentlicht 22.07.2026 12:51:43
  • Zuletzt bearbeitet 22.07.2026 19:16:57

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an ...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 10:15:30
  • Zuletzt bearbeitet 09.07.2026 19:36:15

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurement...

  • EPSS 0.08%
  • Veröffentlicht 07.07.2026 15:48:04
  • Zuletzt bearbeitet 09.07.2026 20:16:29

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across ...

  • EPSS 0.31%
  • Veröffentlicht 07.07.2026 13:54:20
  • Zuletzt bearbeitet 09.07.2026 20:20:52

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the...

  • EPSS 0.63%
  • Veröffentlicht 07.07.2026 09:17:36
  • Zuletzt bearbeitet 08.07.2026 21:16:46

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet t...

  • EPSS 0.21%
  • Veröffentlicht 18.06.2026 14:44:32
  • Zuletzt bearbeitet 30.06.2026 11:16:28

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsyst...