The vendor explicitly identifies these products as affected by this CVE.
- redhat-ds:12/389-ds-base.src as a component of Red Hat Directory Server 12
- 389-ds-base.src as a component of Red Hat Directory Server 13
- 389-ds-base as a component of Red Hat Enterprise Linux 6
- 389-ds-base-devel as a component of Red Hat Enterprise Linux 6
- 389-ds-base-libs as a component of Red Hat Enterprise Linux 6
- 389-ds-base.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
