A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
The product does not properly control the allocation and maintenance of a limited resource.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2018:2757 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14638 | issue tracking third party advisory mitigation |
https://pagure.io/389-ds-base/c/78fc627accacfa4061ce48977e22301f81ea8d73 | issue tracking third party advisory mitigation |