Red Hat, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with 389-ds-base.
Products
Clear product- keycloak6 vulnerabilities
- 389-ds-base3 vulnerabilities
- ceph3 vulnerabilities
- Gluster Storage for RHEL 63 vulnerabilities
- postgresql3 vulnerabilities
- resteasy3 vulnerabilities
- Ansible Tower2 vulnerabilities
- etcd2 vulnerabilities
- GlusterFS2 vulnerabilities
- Moodle2 vulnerabilities
- Wildfly2 vulnerabilities
- ansible1 vulnerability
- atomic-openshift1 vulnerability
- augeas1 vulnerability
- Cairo1 vulnerability
- CloudForms1 vulnerability
- curl1 vulnerability
- cygwin1 vulnerability
- dnsdist1 vulnerability
- DPDK1 vulnerability
- EAP-51 vulnerability
- fedora-arm-installer1 vulnerability
- hawtio1 vulnerability
- hibernate-validator1 vulnerability
- HornetQ/Artemis1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-1054HIGH | An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service. | CVSS7.5v3.0 | EPSS4.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-15134HIGH | A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service. | CVSS7.5v3.0 | EPSS3.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-15135HIGH | It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances. CWE-287Jan 24, 2018 | CVSS8.1v3.0 | EPSS3.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |