VDB
ALINUX2-SA-2024%3A0026
ALINUX2-SA-2024%3A0026
PUBLISHED
CVSS 5.699999809265137 MEDIUM
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input. CVE-2024-3657: A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
Risk Scores
CVSS 3.1
5.699999809265137
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | 389-ds-base |
Timeline
- Aug 7, 2024 CVE Published
- Aug 7, 2024 CVE Updated