446
VMScore

CVE-2022-0918

Published: 16/03/2022 Updated: 24/04/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability exists in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

port389 389-ds-base 1.4.0

redhat enterprise linux 8.0

Vendor Advisories

Debian Bug report logs - #1016445 389-ds-base: CVE-2022-0918 Package: src:389-ds-base; Maintainer for src:389-ds-base is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 31 Jul 2022 19:36:07 UTC Severity: grave Tags: security, upstream ...
Synopsis Moderate: 389-ds-base security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security ha ...
Synopsis Moderate: redhat-ds:11 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat Directory Server 115 is now availableRed Hat Product Security has rated this update as having a security ...
Synopsis Moderate: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 9Red Hat Product Security ha ...
概述 Moderate: 389-ds:14 security update 类型/严重性 Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems 标题 An update for the 389-ds:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this up ...
Synopsis Moderate: 389-ds:14 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the 389-ds:14 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Se ...
A double free was found in the way 389-ds-base handles virtual attributes context in persistent searches An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash (CVE-2021-4091) A vulnerability was found in the 389 Directory Server that allows an unauthenticated attacker with network access to the L ...
A vulnerability was found in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service The denial of service is triggered by a single message sent over a TCP connection No bind or other authentication is required This message triggers a segmentation fault that results in sl ...