Candidate: CVE-2021-3480 PublicDate: 2021-05-20 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3480 https://bugzilla.redhat.com/show_bug.cgi?id=1944640 https://pagure.io/slapi-nis/c/c7417ea2d534712e559b56ed45baa91c5d3d44db?branch=master Description: A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability. Ubuntu-Description: Notes: sbeattie> Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_slapi-nis: upstream: https://pagure.io/slapi-nis/c/c7417ea2d534712e559b56ed45baa91c5d3d44db?branch=master upstream_slapi-nis: needs-triage precise/esm_slapi-nis: DNE trusty_slapi-nis: ignored (out of standard support) trusty/esm_slapi-nis: DNE xenial_slapi-nis: ignored (out of standard support) bionic_slapi-nis: needs-triage focal_slapi-nis: needs-triage groovy_slapi-nis: ignored (reached end-of-life) hirsute_slapi-nis: ignored (reached end-of-life) impish_slapi-nis: needs-triage jammy_slapi-nis: needs-triage devel_slapi-nis: needs-triage