CVE-2018-14624 is a denial-of-service vulnerability affecting 389-ds-base versions up to 1.3.7.10, 1.3.8.8, and 1.4.0.16, impacting Debian, Fedora, and Red Hat distributions. The flaw stems from improper handling of the error log file lock during re-opening, allowing an unauthenticated attacker to crash the slapd daemon by flooding it with modifications to a large DN. Rated High severity with a CVSS score of 7.5, this vulnerability has a low attack complexity and results in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.7.10CPE matchmatch criteria | cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:* | ||
>= 1.3.8.0, <= 1.3.8.8CPE matchmatch criteria | cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:* | ||
>= 1.4.0.0, <= 1.4.0.16CPE matchmatch criteria | cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.