UBUNTU-CVE-2017-2668
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-2668
Summary:
Details: 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
References: https://ubuntu.com/security/CVE-2017-2668, https://bugzilla.redhat.com/show_bug.cgi?id=1436575, https://pagure.io/389-ds-base/issue/49184, https://git.centos.org/raw/rpms!389-ds-base!/c9e5dad69e2b497f118efac56f43cc6c74b6a695/SOURCES!0072-fix-for-cve-2017-2668-simple-return-text-if-suffix-n.patch, https://www.cve.org/CVERecord?id=CVE-2017-2668
Affected packages
Package
Name: 389-ds-base
Purl: pkg:deb/ubuntu/389-ds-base?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
