389-ds-base is an LDAPv3 compliant server which includes the LDAP server and command line utilities for server administration.
Security Fix(es):
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.(CVE-2024-5953)
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.(CVE-2024-6237)
{
"severity": "Medium"
}{
"noarch": [
"cockpit-389-ds-3.1.1-1.oe2403.noarch.rpm",
"python3-lib389-3.1.1-1.oe2403.noarch.rpm"
],
"aarch64": [
"389-ds-base-3.1.1-1.oe2403.aarch64.rpm",
"389-ds-base-debuginfo-3.1.1-1.oe2403.aarch64.rpm",
"389-ds-base-debugsource-3.1.1-1.oe2403.aarch64.rpm",
"389-ds-base-devel-3.1.1-1.oe2403.aarch64.rpm",
"389-ds-base-help-3.1.1-1.oe2403.aarch64.rpm",
"389-ds-base-snmp-3.1.1-1.oe2403.aarch64.rpm"
],
"x86_64": [
"389-ds-base-3.1.1-1.oe2403.x86_64.rpm",
"389-ds-base-debuginfo-3.1.1-1.oe2403.x86_64.rpm",
"389-ds-base-debugsource-3.1.1-1.oe2403.x86_64.rpm",
"389-ds-base-devel-3.1.1-1.oe2403.x86_64.rpm",
"389-ds-base-help-3.1.1-1.oe2403.x86_64.rpm",
"389-ds-base-snmp-3.1.1-1.oe2403.x86_64.rpm"
],
"src": [
"389-ds-base-3.1.1-1.oe2403.src.rpm"
]
}