CVE-2021-3514

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
28/05/2021
Last modified:
24/04/2023

Description

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*