Redhat

389 Directory Server

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 09.06.2026 13:02:59
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server duri...

  • EPSS 0.18%
  • Veröffentlicht 09.06.2026 13:02:53
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

  • EPSS 0.58%
  • Veröffentlicht 09.06.2026 13:02:53
  • Zuletzt bearbeitet 18.08.2026 15:16:48

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure...

  • EPSS 0.16%
  • Veröffentlicht 09.06.2026 12:57:59
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.

  • EPSS 0.18%
  • Veröffentlicht 09.06.2026 12:57:59
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

  • EPSS 0.24%
  • Veröffentlicht 08.06.2026 16:17:59
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin ...

  • EPSS 0.82%
  • Veröffentlicht 20.05.2026 09:00:42
  • Zuletzt bearbeitet 21.08.2026 12:16:37

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request c...

  • EPSS 0.92%
  • Veröffentlicht 09.07.2024 17:15:48
  • Zuletzt bearbeitet 21.11.2024 09:49:15

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

  • EPSS 0.57%
  • Veröffentlicht 28.05.2024 12:15:08
  • Zuletzt bearbeitet 26.06.2026 05:16:26

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.

  • EPSS 0.31%
  • Veröffentlicht 12.02.2024 13:15:09
  • Zuletzt bearbeitet 18.02.2025 11:15:11

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.