A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
                
            References
                    | Link | Resource | 
|---|---|
| https://access.redhat.com/errata/RHSA-2024:4997 | |
| https://access.redhat.com/errata/RHSA-2024:5192 | |
| https://access.redhat.com/security/cve/CVE-2024-6237 | Vendor Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=2293579 | Issue Tracking | 
| https://github.com/389ds/389-ds-base/issues/5989 | Issue Tracking | 
| https://access.redhat.com/security/cve/CVE-2024-6237 | Vendor Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=2293579 | Issue Tracking | 
| https://github.com/389ds/389-ds-base/issues/5989 | Issue Tracking | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 09:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://access.redhat.com/security/cve/CVE-2024-6237 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2293579 - Issue Tracking | |
| References | () https://github.com/389ds/389-ds-base/issues/5989 - Issue Tracking | 
12 Aug 2024, 13:38
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
06 Aug 2024, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
12 Jul 2024, 17:14
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.5 | 
| CWE | NVD-CWE-noinfo | |
| References | () https://access.redhat.com/security/cve/CVE-2024-6237 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2293579 - Issue Tracking | |
| References | () https://github.com/389ds/389-ds-base/issues/5989 - Issue Tracking | |
| Summary | 
 | |
| First Time | Redhat 389 Directory Server Redhat directory Server Redhat enterprise Linux Redhat | |
| CPE | cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | 
09 Jul 2024, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
09 Jul 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-07-09 17:15
Updated : 2024-11-21 09:49
NVD link : CVE-2024-6237
Mitre link : CVE-2024-6237
CVE.ORG link : CVE-2024-6237
JSON object : View
Products Affected
                redhat
- enterprise_linux
- 389_directory_server
- directory_server
CWE
                