The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
CVSS Details
- CVSS 3.1 Base Score: 3.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade 389-ds-baseUpgrade 389-ds-base-libsUpgrade 389-ds-base-devel | Dec 1, 2016 | Jul 3, 2012 |
| Freebsd | — | Upgrade apache22-itk-mpmUpgrade apache22-worker-mpmUpgrade apache22-peruser-mpmUpgrade apache22Upgrade apache22-event-mpm | Dec 10, 2025 | Nov 2, 2012 |
| Oracle_linux | — | Upgrade 389-ds-base-develUpgrade 389-ds-base-libsUpgrade 389-ds-base | Oct 16, 2024 | Jul 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub