When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/389ds/389-ds-base/issues/4711 | third party advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | mailing list |