#VU60867 Use-after-free in 389-ds-base - CVE-2021-4091
Published: February 25, 2022
389-ds-base
389 Directory Server Project
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error when processing virtual attributes context in persistent searches. A remote user can send specially crafted search requests to the directory server, trigger a use-after-free error and crash the server.