Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sumit Bose

Pesquisador deRed Hat
#20211de 53,638
12.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2015-4561
7.8
2015-03-26
389 Directory Server · Slapi-Nis Plug-In · CVE-2015-0283
**Name of the Vulnerable Software and Affected Versions** slapi-nis plug-in versions prior to 0.54.2 **Description** The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and CPU consumption. This can be achieved by requesting a group with a large number of members or a user that belongs to a large number of groups. **Recommendations** For slapi-nis plug-in versions prior to 0.54.2, update to version 0.54.2 or later to resolve the issue.
PT-2013-2245
5.0
2013-03-26
Red Hat · 389 Directory Server · CVE-2013-0336
**Name of the Vulnerable Software and Affected Versions** FreeIPA versions prior to 3.2.0 **Description** The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a connection request without a username or dn. This is related to the 389 directory server. **Recommendations** For versions prior to 3.2.0, update to version 3.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the ipapwd chpwop function in the directory server until a patch is available.