389-ds-base-1.3.8.4-25.1.el7

エラータID: AXSA:2019-3946:02

Release date: 
Monday, August 5, 2019 - 07:57
Subject: 
389-ds-base-1.3.8.4-25.1.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

* 389-ds-base: DoS via hanging secured connections (CVE-2019-3883)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* Previously, if you were using the PAM plugin and attempted to bind as a dn that doesn't exist, the server would crash. This has now been fixed. (BZ#1718184)

CVE-2019-3883
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. 389-ds-base-1.3.8.4-25.1.el7.src.rpm
    MD5: b1c789bd981e254a622703f910207959
    SHA-256: d9f86ec1ccce880e6f6c4c330e383ad3bf89285797bba6cbe1d37c6ae0e694a0
    Size: 3.64 MB

Asianux Server 7 for x86_64
  1. 389-ds-base-1.3.8.4-25.1.el7.x86_64.rpm
    MD5: 67322f542fd781cc9a98746b45d680af
    SHA-256: 1dfb5899c186afc7556c2738240e271da21010ada928fd6838a1dc6d548ddf9a
    Size: 1.72 MB
  2. 389-ds-base-libs-1.3.8.4-25.1.el7.x86_64.rpm
    MD5: c6e4df3d13dbd5778c149825b5b3c262
    SHA-256: 9f5829d2b26254a5b5ece9a4da24f0bc9cd00c65a43e42f27eea08da456427ea
    Size: 699.35 kB