A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2030307 | issue tracking patch vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | mailing list |