Security Advisory

CVE-2022-0918

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-16 14:04:23
Last updated 2025-11-03 20:34:32
Assigner redhat
State PUBLISHED

Description

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.