CVE-2024-6237

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

12 Aug 2024, 13:38

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:5192 -

06 Aug 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:4997 -

12 Jul 2024, 17:14

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en 389 Directory Server. Este fallo permite que un usuario no autenticado provoque un fallo sistemático del servidor mientras envía una solicitud de búsqueda extendida específica, lo que lleva a una denegación de servicio.
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2024-6237 - () https://access.redhat.com/security/cve/CVE-2024-6237 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2293579 - () https://bugzilla.redhat.com/show_bug.cgi?id=2293579 - Issue Tracking
References () https://github.com/389ds/389-ds-base/issues/5989 - () https://github.com/389ds/389-ds-base/issues/5989 - Issue Tracking
First Time Redhat directory Server
Redhat enterprise Linux
Redhat 389 Directory Server
Redhat

09 Jul 2024, 18:18

Type Values Removed Values Added
References
  • () https://github.com/389ds/389-ds-base/issues/5989 -

09 Jul 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 17:15

Updated : 2024-08-29 18:15


NVD link : CVE-2024-6237

Mitre link : CVE-2024-6237

CVE.ORG link : CVE-2024-6237


JSON object : View

Products Affected

redhat

  • 389_directory_server
  • directory_server
  • enterprise_linux
CWE
NVD-CWE-noinfo CWE-230

Improper Handling of Missing Values