• CVE-2025-2487

发布时间: 2025年4月3日

修改时间: 2025年4月3日

概要

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 4.9
Attack Complexity Low
Privileges Required High
Scope Unchanged
Integrity None
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2468 three-eight-nine-ds-base security update 2025年5月1日

影响产品

产品 状态
V6 three-eight-nine-ds-base Fixed