PT-2022-6594 · Red Hat+5 · 389 Directory Server+6

Tbordaz

·

Published

2022-03-15

·

Updated

2025-01-20

·

CVE-2022-0918

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions 389 Directory Server (affected versions not specified)
Description A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5823
ALSA-2022:8162
ALSA-2022_0889
ALSA-2022_5823
ALSA-2024_3837
ALSA-2024_4235
ALSA-2024_5192
ALSA-2024_6569
BDU:2023-02637
CESA-2022_5239
CESA-2022_5823
CVE-2022-0918
DLA-3399-1
DLA-4021-1
ELSA-2022-5239
ELSA-2022-5823
ELSA-2022-8162
MGASA-2022-0134
OPENSUSE-SU-2022:1100-1
OPENSUSE-SU-2022_1100-1
OPENSUSE-SU-2024:11963-1
RHSA-2022:2210
RHSA-2022:5239
RHSA-2022:5620
RHSA-2022:5823
RHSA-2022:8162
RHSA-2022:8976
RHSA-2022_5239
RHSA-2022_5823
RHSA-2022_8162
RLSA-2022:5823
RLSA-2022:8162
RLSA-2022_5823
RLSA-2022_8162
SUSE-SU-2022:1100-1
SUSE-SU-2022:1102-1
SUSE-SU-2022:1139-1
SUSE-SU-2022:2163-1
SUSE-SU-2022_1100-1
SUSE-SU-2022_1102-1
SUSE-SU-2022_1139-1
SUSE-SU-2022_2163-1

Affected Products

389 Directory Server
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse