4
CVSSv2

CVE-2018-10935

Published: 11/09/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat 389 directory server

Vendor Advisories

Debian Bug report logs - #906985 389-ds-base: CVE-2018-10935: ldapsearch with server side sort allows users to cause a crash Package: src:389-ds-base; Maintainer for src:389-ds-base is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 22 A ...
Synopsis Moderate: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
Synopsis Moderate: 389-ds-base security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
A vulnerability was discovered in 389-ds-base The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency() An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash(CVE-2018-14624) A race condition was found in the way 389-ds-base handles persistent se ...
A vulnerability was discovered in 389-ds-base The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency() An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash(CVE-2018-14624) A race condition was found in the way 389-ds-base handles persistent se ...