5
CVSSv2

CVE-2021-3480

Published: 20/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in slapi-nis in versions prior to 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated malicious user to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

slapi-nis project slapi-nis

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #988727 389-ds-base: CVE-2021-3514 Package: 389-ds-base; Maintainer for 389-ds-base is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Source for 389-ds-base is src:389-ds-base (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 18 May 2021 18:33 ...
Debian Bug report logs - #988736 slapi-nis: CVE-2021-3480 Package: src:slapi-nis; Maintainer for src:slapi-nis is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 18 May 2021 18:33:05 UTC Severity: grave Tags: security Found in version slapi ...
A flaw was found in slapi-nis A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server The highest threat from this vulnerability is to system availability (CVE-2021-3480) ...
A flaw was found in slapi-nis A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server The highest threat from this vulnerability is to system availability ...