A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
Workaround:
The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:4997 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:5192 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-6237 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2293579 | issue tracking |
https://github.com/389ds/389-ds-base/issues/5989 | issue tracking |