7.5
CVSSv3

CVE-2021-4091

Published: 18/02/2022 Updated: 24/04/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

port389 389-ds-base

redhat enterprise linux workstation 7.0

redhat enterprise linux for scientific computing 7.0

redhat enterprise linux server 7.0

redhat enterprise linux for power little endian 7.0

redhat enterprise linux for power big endian 7.0

redhat enterprise linux for ibm z systems 7.0

redhat enterprise linux desktop 7

Vendor Advisories

Synopsis Low: 389-ds-base security and bug fix update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as h ...
Synopsis Moderate: redhat-ds:113 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the redhat-ds:11 module is now available for Red Hat Directory Server 113 for RHEL 8Red Hat Prod ...
Synopsis Low: 389-ds:14 security and bug fix update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the 389-ds:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this up ...
Synopsis Low: 389-ds:14 security and bug fix update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the 389-ds:14 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product ...
A double free was found in the way 389-ds-base handles virtual attributes context in persistent searches An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash (CVE-2021-4091) A vulnerability was found in the 389 Directory Server that allows an unauthenticated attacker with network access to the L ...
A double free was found in the way 389-ds-base handles virtual attributes context in persistent searches An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash (CVE-2021-4091) ...
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash ...