A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
389_directory_server | Fedoraproject | * | 1.3.8.4 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | 389-ds-base-0:1.3.7.5-28.el7_5 | * |
389-ds-base | Ubuntu | bionic | * |
389-ds-base | Ubuntu | cosmic | * |
389-ds-base | Ubuntu | esm-apps/bionic | * |
389-ds-base | Ubuntu | esm-apps/xenial | * |
389-ds-base | Ubuntu | trusty | * |
389-ds-base | Ubuntu | upstream | * |
389-ds-base | Ubuntu | xenial | * |