389-ds-base-1.3.10.2-16.el7

エラータID: AXSA:2022-3281:02

Release date: 
Tuesday, June 28, 2022 - 13:38
Subject: 
389-ds-base-1.3.10.2-16.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

* 389-ds-base: sending crafted message could result in DoS (CVE-2022-0918)
* 389-ds-base: expired password was still allowed to access the database (CVE-2022-0996)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* Log the Auto Member invalid regex rules in the LDAP errors log.

Enhancement(s):

* RFE - Provide an option to abort an Auto Member rebuild task.

CVE-2022-0918
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
CVE-2022-0996
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. 389-ds-base-1.3.10.2-16.el7.src.rpm
    MD5: 82a8f2a3f89493f9abe134a2391ceb3f
    SHA-256: 999a2b9666710ab02c65c155f2a33425bde08d95a4268bc12ace3ecbebc4039c
    Size: 3.74 MB

Asianux Server 7 for x86_64
  1. 389-ds-base-1.3.10.2-16.el7.x86_64.rpm
    MD5: d7afedd1f1f37b6dee7bacaa1592c376
    SHA-256: e3149765c05ab5934861d16e545505f658f7b93e4f7bd637553a25090f54391d
    Size: 1.74 MB
  2. 389-ds-base-libs-1.3.10.2-16.el7.x86_64.rpm
    MD5: 9f9ad3eaa5d5286aed8b760373bc280e
    SHA-256: 8102fb4f46bde0709df238a83ee29c1a8378775b07bc731a240822636d2a7602
    Size: 715.43 kB