LDAP: Red Hat 389 Directory Server Server-Side-Sort Denial of Service
This signature detects attempt to exploit a denial-of-service vulnerability which has been reported in 389 Directory Server.A remote, unauthenticated attacker could send LDAP requests with server-side-sort enabled to trigger the vulnerability. Successful exploitation of the vulnerability could cause the ns-slapd process to abnormally terminate.
Extended Description
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
Affected Products
Redhat 389_directory_server
References
CVE: CVE-2018-10935
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Redhat
4.0