|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2018-14624: 389-ds: Server crash through modify command with large DN | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | William Brown <william.brown> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | abergmann, dakechi, smash_bz, william.brown |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/213571/ | ||
| Whiteboard: | CVSSv3:RedHat:CVE-2018-14624:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVSSv3:SUSE:CVE-2018-14624:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVSSv2:NVD:CVE-2018-14624:5.0:(AV:N/AC:L/Au:N/C:N/I:N/A:P) CVSSv3:NVD:CVE-2018-14624:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2018-08-31 06:06:14 UTC
An update to 389-ds source to 1.4.0.22 is recommended to resolve this and many other issues. SUSE-SU-2019:1207-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1076530,1096368,1105606,1106699 CVE References: CVE-2017-15134,CVE-2017-15135,CVE-2018-10850,CVE-2018-10935,CVE-2018-14624 Sources used: SUSE Linux Enterprise Module for Server Applications 15 (src): 389-ds-1.4.0.3-4.7.52 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): 389-ds-1.4.0.3-4.7.52 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2019:1397-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1076530,1096368,1105606,1106699 CVE References: CVE-2017-15134,CVE-2017-15135,CVE-2018-10850,CVE-2018-10935,CVE-2018-14624 Sources used: openSUSE Leap 15.0 (src): 389-ds-1.4.0.3-lp150.3.3.1 released SUSE-SU-2019:1207-2: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1076530,1096368,1105606,1106699 CVE References: CVE-2017-15134,CVE-2017-15135,CVE-2018-10850,CVE-2018-10935,CVE-2018-14624 Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP1 (src): 389-ds-1.4.0.3-4.7.52 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): 389-ds-1.4.0.3-4.7.52 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. This is an autogenerated message for OBS integration: This bug (1106699) was mentioned in https://build.opensuse.org/request/show/793266 15.1 / 389-ds |