MEDIUM · 5.5

CVE-2024-1062

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

Vulnerability Description

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Redhat389 Directory Server< 2.2.0
RedhatDirectory Server-
FedoraprojectFedora39
RedhatEnterprise Linux Eus9.2
RedhatEnterprise Linux8.0
RedhatEnterprise Linux For Arm 64 Eus8.6
RedhatEnterprise Linux For Ibm Z Systems9.2
RedhatEnterprise Linux For Ibm Z Systems Eus8.8
RedhatEnterprise Linux For Power Little Endian Eus8.8
RedhatEnterprise Linux Server Aus8.6
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions8.6
RedhatEnterprise Linux Server Tus8.6
RedhatEnterprise Linux Update Services For Sap Solutions8.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-1062?

CVE-2024-1062 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

How severe is CVE-2024-1062?

CVE-2024-1062 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-1062?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat 389 Directory Server, Redhat Directory Server, Fedoraproject Fedora, Redhat Enterprise Linux Eus, Redhat Enterprise Linux.