MGASA-2018-0162

Source
https://advisories.mageia.org/MGASA-2018-0162.html
Import Source
https://advisories.mageia.org/MGASA-2018-0162.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0162
Related
Published
2018-03-07T20:37:26Z
Modified
2018-03-07T20:21:06Z
Summary
Updated 389-ds-base packages fix CVE-2018-1054
Details

389-ds-base has been updated to fix a security issue.

A flaw was found in 389 Directory Server that affects all versions. An improper handling of the search feature with an extended filter, when read access on <attribute_name> is enabled, in SetUnicodeStringFromUTF_8 function in collate.c, can lead to out-of-bounds memory operations. This may allow a remote unauthenticated attacker to trigger a server crash, thus resulting in denial of service. (CVE-2018-1054)

References
Credits

Affected packages

Mageia:6 / 389-ds-base

Package

Name
389-ds-base
Purl
pkg:rpm/mageia/389-ds-base?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.5.17-1.3.mga6

Ecosystem specific

{
    "section": "core"
}