Red Hat · 389-Ds-Base · CVE-2017-15134
Name of the Vulnerable Software and Affected Versions:
389-ds-base versions 1.3.6.x through 1.3.6.12
389-ds-base versions 1.3.7.x through 1.3.7.8
389-ds-base versions 1.4.x through 1.4.0.4
Description:
A stack buffer overflow flaw was found in the way 389-ds-base handled certain LDAP search filters. This issue could allow a remote, unauthenticated attacker to potentially make ns-slapd crash via a specially crafted LDAP request, resulting in denial of service.
Recommendations:
For 389-ds-base versions 1.3.6.x through 1.3.6.12, update to version 1.3.6.13 or later.
For 389-ds-base versions 1.3.7.x through 1.3.7.8, update to version 1.3.7.9 or later.
For 389-ds-base versions 1.4.x through 1.4.0.4, update to version 1.4.0.5 or later.