|
|
Log in / Subscribe / Register

Mageia alert MGASA-2018-0245 (389-ds-base)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2018-0245: Updated 389-ds-base packages fix security vulnerability
Date:  Wed, 16 May 2018 10:25:57 +0200
Message-ID:  <20180516082557.E44E29FB82@duvel.mageia.org>

MGASA-2018-0245 - Updated 389-ds-base packages fix security vulnerability Publication date: 16 May 2018 URL: https://advisories.mageia.org/MGASA-2018-0245.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-1089 Description: 389-ds-base did not properly handle characters needed to be escaped in its query filter. This could result in buffer overflows, from the heap or the stack, on larger filters. An unauthenticated attacker could send a specially crafted LDAP request and crash the server (CVE-2018-1089). References: - https://bugs.mageia.org/show_bug.cgi?id=23005 - https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1089 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1089 SRPMS: - 6/core/389-ds-base-1.3.5.17-1.5.mga6


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds