Candidate: CVE-2018-10850 PublicDate: 2018-06-13 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10850 Description: 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=1588056 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H [5.9 MEDIUM] Patches_389-ds-base: upstream_389-ds-base: released (1.4.0.13-1) precise/esm_389-ds-base: DNE trusty_389-ds-base: ignored (reached end-of-life) trusty/esm_389-ds-base: DNE (trusty was needs-triage) xenial_389-ds-base: ignored (end of standard support, was needed) artful_389-ds-base: ignored (reached end-of-life) bionic_389-ds-base: needed cosmic_389-ds-base: ignored (reached end-of-life) disco_389-ds-base: not-affected (1.4.0.13-1) eoan_389-ds-base: not-affected (1.4.0.13-1) focal_389-ds-base: not-affected (1.4.0.13-1) groovy_389-ds-base: not-affected (1.4.0.13-1) hirsute_389-ds-base: not-affected (1.4.0.13-1) impish_389-ds-base: not-affected (1.4.0.13-1) jammy_389-ds-base: not-affected (1.4.0.13-1) devel_389-ds-base: not-affected (1.4.0.13-1)