VDB

ALINUX2-SA-2024%3A0026

ALINUX2-SA-2024%3A0026 PUBLISHED CVSS 5.699999809265137 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. CVE-2024-3657: A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

Risk Scores

CVSS 3.1
5.699999809265137
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alibaba Cloud389-ds-base

Timeline

  • Aug 7, 2024 CVE Published
  • Aug 7, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›