PT-2018-3494 · Red Hat+2 · 389 Directory Server+3

Sam Fowler

·

Published

2018-08-30

·

Updated

2024-06-15

·

CVE-2018-10935

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: 389 Directory Server (affected versions not specified)
Description: The issue is related to an uncontrolled resource consumption in the 389 Directory Server. It can be exploited by a remote attacker to cause a crash in the server by using ldapsearch with server-side sort. This can lead to a denial-of-service condition.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02769
CESA-2018_2757
CVE-2018-10935
DLA-1483-1
MGASA-2018-0404
OPENSUSE-SU-2019:1397-1
OPENSUSE-SU-2019_1397-1
OPENSUSE-SU-2024:10593-1
RHSA-2018:2757
RHSA-2018_2757
SUSE-SU-2019:1207-1
SUSE-SU-2019:1207-2
SUSE-SU-2019:2155-1

Affected Products

389 Directory Server
Centos
Red Hat
Suse