Impact
A missing NULL pointer check in the paged results handling of op_shared_search in 389 Directory Server allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests that use the USE_ONE_BACKEND control. This results in a denial of service because the server terminates unexpectedly.
Affected Systems
Red Hat Directory Server versions 11 through 13, and Red Hat Enterprise Linux releases 6, 7, 8, 9, and 10 are affected. The vulnerability resides in the LDAP server package distributed with these operating systems and numbered accordingly.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated remote attacker who can send crafted LDAP search requests over the network. No elevated privileges or local access are required. The exploit leads to a crash of the LDAP service, causing denial of service for clients relying on directory services.
OpenCVE Enrichment