CVE-2024-2199

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:3591 - () https://access.redhat.com/errata/RHSA-2024:3591 -
References () https://access.redhat.com/errata/RHSA-2024:3837 - () https://access.redhat.com/errata/RHSA-2024:3837 -
References () https://access.redhat.com/errata/RHSA-2024:4092 - () https://access.redhat.com/errata/RHSA-2024:4092 -
References () https://access.redhat.com/errata/RHSA-2024:4209 - () https://access.redhat.com/errata/RHSA-2024:4209 -
References () https://access.redhat.com/errata/RHSA-2024:4210 - () https://access.redhat.com/errata/RHSA-2024:4210 -
References () https://access.redhat.com/errata/RHSA-2024:4235 - () https://access.redhat.com/errata/RHSA-2024:4235 -
References () https://access.redhat.com/errata/RHSA-2024:4633 - () https://access.redhat.com/errata/RHSA-2024:4633 -
References () https://access.redhat.com/security/cve/CVE-2024-2199 - () https://access.redhat.com/security/cve/CVE-2024-2199 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2267976 - () https://bugzilla.redhat.com/show_bug.cgi?id=2267976 -

21 Aug 2024, 13:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:5690 -

18 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4633 -

02 Jul 2024, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4235 -

02 Jul 2024, 12:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4209 -
  • () https://access.redhat.com/errata/RHSA-2024:4210 -

25 Jun 2024, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4092 -

12 Jun 2024, 10:15

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad de denegación de servicio en el servidor ldap 389-ds-base. Este problema puede permitir que un usuario autenticado provoque una falla del servidor al modificar "userPassword" utilizando una entrada con formato incorrecto.
References
  • () https://access.redhat.com/errata/RHSA-2024:3591 -
  • () https://access.redhat.com/errata/RHSA-2024:3837 -

28 May 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-28 12:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2199

Mitre link : CVE-2024-2199

CVE.ORG link : CVE-2024-2199


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation