389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle...
Vulnerability Description
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1089
Credits & Attribution
No credits recorded in the NVD database.
References
More from unspecified
View All →Affected Vendor
unspecified
View all reports →