UBUNTU-CVE-2022-2850
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-2850
Summary:
Details: A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
References: https://ubuntu.com/security/CVE-2022-2850, https://bugzilla.redhat.com/show_bug.cgi?id=2118691, https://github.com/389ds/389-ds-base/issues/4711#issuecomment-1205100979, https://github.com/389ds/389-ds-base/issues/5418, https://www.cve.org/CVERecord?id=CVE-2022-2850
Affected packages
Package
Name: 389-ds-base
Purl: pkg:deb/ubuntu/389-ds-base?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
