Redhat

389 Directory Server

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 03.08.2026 14:55:33
  • Zuletzt bearbeitet 09.08.2026 13:54:50

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as fai...

  • EPSS 0.69%
  • Veröffentlicht 31.07.2026 09:18:58
  • Zuletzt bearbeitet 18.08.2026 15:16:48

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated repl...

  • EPSS 0.87%
  • Veröffentlicht 31.07.2026 09:18:50
  • Zuletzt bearbeitet 18.08.2026 15:16:49

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checkin...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 10:15:30
  • Zuletzt bearbeitet 09.07.2026 19:36:15

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurement...

  • EPSS 0.08%
  • Veröffentlicht 07.07.2026 15:48:04
  • Zuletzt bearbeitet 09.07.2026 20:16:29

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across ...

  • EPSS 0.31%
  • Veröffentlicht 07.07.2026 13:54:20
  • Zuletzt bearbeitet 09.07.2026 20:20:52

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the...

  • EPSS 0.21%
  • Veröffentlicht 18.06.2026 14:44:32
  • Zuletzt bearbeitet 30.06.2026 11:16:28

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsyst...

  • EPSS 0.23%
  • Veröffentlicht 17.06.2026 14:27:27
  • Zuletzt bearbeitet 28.06.2026 00:22:17

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validat...

  • EPSS 0.28%
  • Veröffentlicht 09.06.2026 13:11:40
  • Zuletzt bearbeitet 07.08.2026 06:16:52

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An ...

  • EPSS 0.29%
  • Veröffentlicht 09.06.2026 13:09:29
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause ex...