7.1
CVSSv2

CVE-2018-10850

Published: 13/06/2018 Updated: 15/05/2019
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

389-ds-base prior to 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject 389 directory server

debian debian linux 8.0

redhat enterprise linux 7.0

redhat enterprise linux server aus 7.6

redhat enterprise linux server tus 7.6

redhat enterprise linux workstation 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server eus 7.6

redhat enterprise linux server eus 7.5

redhat enterprise linux server 7.0

Vendor Advisories

Synopsis Moderate: 389-ds-base security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
Debian Bug report logs - #903501 389-ds-base: CVE-2018-10850 Package: src:389-ds-base; Maintainer for src:389-ds-base is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 10 Jul 2018 19:21:01 UTC Severity: important Tags: security, upstre ...
A vulnerability was discovered in 389-ds-base The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency() An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash(CVE-2018-14624) A race condition was found in the way 389-ds-base handles persistent se ...
A vulnerability was discovered in 389-ds-base The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency() An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash(CVE-2018-14624) A race condition was found in the way 389-ds-base handles persistent se ...
A race condition was found in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load An anonymous attacker could use this flaw to trigger a denial of service ...