Candidate: CVE-2021-3514 PublicDate: 2021-05-28 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3514 https://github.com/389ds/389-ds-base/issues/4711 Description: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_389-ds-base: upstream: https://github.com/389ds/389-ds-base/commit/58dbf084a63e6dbbd999bf6a70475fad8255f26a (1.4.4) upstream: https://github.com/389ds/389-ds-base/commit/2e5b526012612d1d6ccace46398bee679a730271 (1.4.3) upstream: https://github.com/389ds/389-ds-base/commit/0bdc258b9405e2b652490023a3241db25ce3165e (1.4.2) upstream_389-ds-base: released (1.4.2.18, 1.4.3.23, 1.4.4.11-2) precise/esm_389-ds-base: DNE trusty_389-ds-base: ignored (out of standard support) trusty/esm_389-ds-base: DNE (trusty was needed) xenial_389-ds-base: ignored (end of standard support, was needed) bionic_389-ds-base: needed focal_389-ds-base: needed groovy_389-ds-base: ignored (reached end-of-life) hirsute_389-ds-base: ignored (reached end-of-life) impish_389-ds-base: released (1.4.4.11-2build1) jammy_389-ds-base: needs-triage devel_389-ds-base: needs-triage