MGASA-2018-0162
Dashboard / Vulnerabilities / MGASA-2018-0162
Summary: Updated 389-ds-base packages fix CVE-2018-1054
Details: 389-ds-base has been updated to fix a security issue. A flaw was found in 389 Directory Server that affects all versions. An improper handling of the search feature with an extended filter, when read access on <attribute_name> is enabled, in SetUnicodeStringFromUTF_8 function in collate.c, can lead to out-of-bounds memory operations. This may allow a remote unauthenticated attacker to trigger a server crash, thus resulting in denial of service. (CVE-2018-1054)
References: https://advisories.mageia.org/MGASA-2018-0162.html, https://bugs.mageia.org/show_bug.cgi?id=22710, http://openwall.com/lists/oss-security/2018/03/06/2
Affected packages
Package
Name: 389-ds-base
Purl: pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
