CVE Advisories
Security vulnerabilities discovered during authorized security research
sudo_provider=ldap trusts entire LDAP tree — helpdesk LDAP write to root
sssd · CWE-269
sudo_provider=ldap trusts entire LDAP tree — helpdesk LDAP write to root (Important, CVSS 8.8). Discovered in sssd.
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND
389-ds-base · CWE-122
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND (Important, CVSS 8.8). Discovered in 389-ds-base.
GPO cache path traversal + Kerberos config injection
sssd · CWE-22
GPO cache path traversal + Kerberos config injection (Important, CVSS 8.2). Discovered in sssd.
Integer overflow in SASL packet length bypasses size limit — RCE on RHEL 8
389-ds-base · CWE-190
Integer overflow in SASL packet length bypasses size limit — RCE on RHEL 8 (Important, CVSS 7.6). Discovered in 389-ds-base.
Content Sync plugin unbounded queue growth and race conditions
389-ds-base · CWE-362
Content Sync plugin unbounded queue growth and race conditions (Moderate, CVSS 6.5). Discovered in 389-ds-base.
Heap buffer overflow in schema objectclass serialization
389-ds-base · CWE-122
Heap buffer overflow in schema objectclass serialization (Moderate, CVSS 6.5). Discovered in 389-ds-base.
NULL pointer dereference in deref control plugin BER parser
389-ds-base · CWE-476
NULL pointer dereference in deref control plugin BER parser (Moderate, CVSS 5.9). Discovered in 389-ds-base.
Use-after-free in schema reload via attr_syntax_swap_ht()
389-ds-base · CWE-416
Use-after-free in schema reload via attr_syntax_swap_ht() (Moderate, CVSS 5.0). Discovered in 389-ds-base.
SMD5 password storage plugin salt length integer underflow crash
389-ds-base · CWE-191
SMD5 password storage plugin salt length integer underflow crash (Moderate, CVSS 4.9). Discovered in 389-ds-base.
PBKDF2 password storage plugin unbounded iteration count DoS
389-ds-base · CWE-400
PBKDF2 password storage plugin unbounded iteration count DoS (Moderate, CVSS 4.9). Discovered in 389-ds-base.
Stack buffer overflow in checkPrefix() algorithm ID parsing
389-ds-base · CWE-121
Stack buffer overflow in checkPrefix() algorithm ID parsing (Low, CVSS 4.9). Discovered in 389-ds-base.
Partial stack address info leak via ber_printf type confusion
389-ds-base · CWE-843
Partial stack address info leak via ber_printf type confusion (Moderate, CVSS 4.3). Discovered in 389-ds-base.
Heap buffer over-read in ldap_utf8prev() via str2simple filter parsing
389-ds-base · CWE-125
Heap buffer over-read in ldap_utf8prev() via str2simple filter parsing (Moderate, CVSS 3.7). Discovered in 389-ds-base.
Heap buffer overflow in audit log password masking
389-ds-base · CWE-122
Heap buffer overflow in audit log password masking (Low, CVSS 3.3). Discovered in 389-ds-base.
Heap out-of-bounds read in LDIF parser str2entry_state_information_from_type
389-ds-base · CWE-125
Heap out-of-bounds read in LDIF parser str2entry_state_information_from_type (Low, CVSS 1.9). Discovered in 389-ds-base.