vulnerability

RHSA-2016:0204: 389-ds-base security and bug fix update

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Feb 16, 2016
Added
Feb 17, 2016
Modified
Oct 30, 2017

Description

The 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server.The base packages include the Lightweight Directory Access Protocol (LDAP)server and command-line utilities for server administration.An infinite-loop vulnerability was discovered in the 389 directory server,where the server failed to correctly handle unexpectedly closed clientconnections. A remote attacker able to connect to the server could use thisflaw to make the directory server consume an excessive amount of CPU andstop accepting connections (denial of service). (CVE-2016-0741)This update fixes the following bugs:Users of 389-ds-base are advised to upgrade to these updated packages,which correct these issues. After installing this update, the 389 serverservice will be restarted automatically.

Solutions

redhat-upgrade-389-ds-baseredhat-upgrade-389-ds-base-debuginforedhat-upgrade-389-ds-base-develredhat-upgrade-389-ds-base-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.