header-logo
Suggest Exploit
vendor:
Directory Server
by:
N/A
N/A
CVSS
N/A
Denial of Service
N/A
CWE
Product Name: Directory Server
Affected Version From: Red Hat Directory Server 7.1
Affected Version To: Red Hat Directory Server 8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A

Red Hat Directory Server Denial of Service Vulnerability

Red Hat Directory Server is prone to a denial-of-service vulnerability because the server fails to handle specially crafted search patterns. An attacker can exploit this issue to consume CPU resources with one search request, effectively blocking additional search requests from executing. Legitimate users may be prevented from authenticating to network resources that use the affected server for authentication.

Mitigation:

Upgrade to the latest version of Red Hat Directory Server.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/30871/info

Red Hat Directory Server is prone to a denial-of-service vulnerability because the server fails to handle specially crafted search patterns.

An attacker can exploit this issue to consume CPU resources with one search request, effectively blocking additional search requests from executing. Legitimate users may be prevented from authenticating to network resources that use the affected server for authentication.

Red Hat Directory Server 7.1 and 8 are affected. 

The following example regular expressions are available:

2.6/AV:N/AC:H/Au:N/C:N/I:N/A:P
4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P