vulnerability
RHSA-2016:0204: 389-ds-base security and bug fix update
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Feb 16, 2016 | Feb 17, 2016 | Oct 30, 2017 |
Description
The 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server.The base packages include the Lightweight Directory Access Protocol (LDAP)server and command-line utilities for server administration.An infinite-loop vulnerability was discovered in the 389 directory server,where the server failed to correctly handle unexpectedly closed clientconnections. A remote attacker able to connect to the server could use thisflaw to make the directory server consume an excessive amount of CPU andstop accepting connections (denial of service). (CVE-2016-0741)This update fixes the following bugs:Users of 389-ds-base are advised to upgrade to these updated packages,which correct these issues. After installing this update, the 389 serverservice will be restarted automatically.
Solutions
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.