The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Workaround:
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:7434 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-8445 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2310110 | issue tracking |