PT-2022-4672 · Unknown+7 · 389-Ds-Base+7
Cedric Buissart
·
Published
2019-02-11
·
Updated
2025-01-20
·
CVE-2021-4091
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
389-ds-base (affected versions not specified)
Description
A double-free issue was found in the way 389-ds-base handles virtual attributes context in persistent searches. This could allow an attacker to send a series of search requests, forcing the server to behave unexpectedly and crash. The vulnerability is related to the use of memory after it has been freed when handling private pblock and duplicated pblock with the same pb vattr context pointer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Double Free
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
389-Ds-Base
Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse