CVE-2024-2199 fix is incomplete on some 389-ds-base versions
Package
389-ds-base
(Red Hat Entreprise Linux 7)
Affected versions
1.4.3.40
Patched versions
None
389-ds-base
1.4.4.20
None
Impact
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, this issue may allow an authenticated user to cause a server crash while modifying
userPassword
using malformed input.Impacted versions are: 389-ds-base 1.4.3.40 and 1.4.4.20.
Note: Versions >= 2.0 that include CVE-2024-2199 are not affected.
References