ZeroHour

CVE-2021-4091

CVSS 3.1
7.5 high
EPSS
2%p80
Published
()
Modified
Description

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

Vendors
port389redhat
Products
389-ds-base, enterprise linux desktop, enterprise linux for ibm z systems, enterprise linux for power big endian, enterprise linux for power little endian, enterprise linux for scientific computing, enterprise linux server, enterprise linux workstation
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.