389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade 389-ds-base | Jul 30, 2024 | Apr 30, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade 389-ds-base-libsUpgrade 389-ds-base | Jul 3, 2018 | Apr 30, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 30, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 30, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub