A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade 389-ds-base-bdb-debuginfoUpgrade 389-ds-base-libs-debuginfoUpgrade 389-ds-baseUpgrade 389-ds-base-bdbUpgrade 389-ds-base-debugsourceUpgrade 389-ds-base-snmp-debuginfoUpgrade 389-ds-base-develNo solution existsUpgrade 389-ds-base-debuginfoUpgrade 389-ds-base-snmpUpgrade 389-ds-base-libsUpgrade python3-lib389 | Aug 26, 2026 | Aug 24, 2026 |
| Rocky_linux | — | Upgrade 389-ds-base-snmp-debuginfoUpgrade 389-ds-base-libsUpgrade 389-ds-base-bdb-debuginfoUpgrade 389-ds-base-libs-debuginfoUpgrade 389-ds-base-develUpgrade 389-ds-baseUpgrade 389-ds-base-snmpUpgrade 389-ds-base-debugsourceUpgrade 389-ds-base-bdbUpgrade 389-ds-base-debuginfo | Sep 15, 2026 | Sep 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub