PT-2024-10420 · Unknown+9 · 389-Ds-Base+9

Robb Gatica

·

Published

2024-04-10

·

Updated

2025-03-16

·

CVE-2024-3657

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions 389-ds-base (affected versions not specified)
Description A flaw in the 389-ds-base directory server is related to insufficient input validation. This issue can be exploited by a remote attacker using a specially-crafted LDAP query, potentially causing a denial of service on the directory server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3837
ALSA-2024:4235
ALT-PU-2024-11458
ALT-PU-2024-11462
ALT-PU-2024-11466
BDU:2025-00952
CESA-2024_4235
CVE-2024-3657
DLA-4021-1
INFSA-2024_3837
INFSA-2024_4235
OESA-2024-1724
OPENSUSE-SU-2024:14227-1
OPENSUSE-SU-2024_3082-1
OPENSUSE-SU-2024_3218-1
OPENSUSE-SU-2024_3257-1
OPENSUSE-SU-2024_3843-1
OPENSUSE-SU-2024_3844-1
RHSA-2024:3591
RHSA-2024:3837
RHSA-2024:4092
RHSA-2024:4209
RHSA-2024:4210
RHSA-2024:4235
RHSA-2024:4633
RHSA-2024:5690
RHSA-2024:6576
RHSA-2024:7458
RHSA-2024_3591
RHSA-2024_3837
RHSA-2024_4235
RHSA-2025:1632
RLSA-2024:3837
RLSA-2024:4235
SUSE-SU-2024:2910-1
SUSE-SU-2024:3082-1
SUSE-SU-2024:3218-1
SUSE-SU-2024:3257-1
SUSE-SU-2024:3843-1
SUSE-SU-2024:3844-1

Affected Products

389-Ds-Base
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse