RHSA-2024:4209HighCVSS 7.5
Red Hat Security Advisory: redhat-ds:11 security and bug fix update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-1062 — 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr) CVE-2024-2199 — 389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c CVE-2024-3657 — 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:4209
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274367
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274401
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4209.json