Vulnerability Details CVE-2021-4091
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-4091
-
cpe:2.3:a:port389:389-ds-base:-
-
cpe:2.3:a:port389:389-ds-base:1.2.1
-
cpe:2.3:a:port389:389-ds-base:1.2.10.0
-
cpe:2.3:a:port389:389-ds-base:1.2.2
-
cpe:2.3:a:port389:389-ds-base:1.2.3
-
cpe:2.3:a:port389:389-ds-base:1.2.4
-
cpe:2.3:a:port389:389-ds-base:1.2.5
-
cpe:2.3:a:port389:389-ds-base:1.2.6
-
cpe:2.3:a:port389:389-ds-base:1.2.6.1
-
cpe:2.3:a:port389:389-ds-base:1.2.7
-
cpe:2.3:a:port389:389-ds-base:1.2.7.1
-
cpe:2.3:a:port389:389-ds-base:1.2.7.2
-
cpe:2.3:a:port389:389-ds-base:1.2.7.3
-
cpe:2.3:a:port389:389-ds-base:1.2.7.4
-
cpe:2.3:a:port389:389-ds-base:1.2.7.5
-
cpe:2.3:a:port389:389-ds-base:1.2.8.0
-
cpe:2.3:a:port389:389-ds-base:1.2.8.1
-
cpe:2.3:a:port389:389-ds-base:1.2.8.2
-
cpe:2.3:a:port389:389-ds-base:1.2.8.3
-
cpe:2.3:a:port389:389-ds-base:1.2.9.0
-
cpe:2.3:a:port389:389-ds-base:1.2.9.1
-
cpe:2.3:a:port389:389-ds-base:1.2.9.10
-
cpe:2.3:a:port389:389-ds-base:1.2.9.2
-
cpe:2.3:a:port389:389-ds-base:1.2.9.3
-
cpe:2.3:a:port389:389-ds-base:1.2.9.4
-
cpe:2.3:a:port389:389-ds-base:1.2.9.5
-
cpe:2.3:a:port389:389-ds-base:1.2.9.6
-
cpe:2.3:a:port389:389-ds-base:1.2.9.8
-
cpe:2.3:a:port389:389-ds-base:1.2.9.9
-
cpe:2.3:o:redhat:enterprise_linux_desktop:7
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0
-
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0
-
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0
-
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0