Input validation error in 389-ds-base - CVE-2024-8445
Published: October 2, 2024
389-ds-base
Anolis OS
openEuler
389-ds-base (Red Hat package)
python-lib389
389-ds-base-tests
389-ds-base-snmp
389-ds-base-libs
389-ds-base-devel
389-ds-base
python3-lib389
389-ds-base-debuginfo
389-ds-base-debugsource
389-ds-base-help
389-ds-base-legacy-tools
cockpit-389-ds
Detailed vulnerability description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input for "userPassword" and perform a denial of service (DoS) attack.
Note, the vulnerability exists due to an insufficient fix for #VU93311 (CVE-2024-2199).