File _patchinfo of Package patchinfo.35601
<patchinfo incident="35601">
<issue tracker="bnc" id="1226277">VUL-0: CVE-2024-5953: 389-ds: malformed userPassword hashes may cause a denial of service</issue>
<issue tracker="bnc" id="1225512">VUL-0: CVE-2024-3657: 389-ds: potential denial of service via specially crafted kerberos AS-REQ request</issue>
<issue tracker="bnc" id="1225507">VUL-0: CVE-2024-2199: 389-ds: malformed userPassword may cause crash at do_modify in slapd/modify.c</issue>
<issue tracker="cve" id="2024-5953"/>
<issue tracker="cve" id="2024-2199"/>
<issue tracker="cve" id="2024-3657"/>
<packager>firstyear</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for 389-ds</summary>
<description>This update for 389-ds fixes the following issues:
- Update to version 1.4.4.20~git3.e7ac6d87:
- CVE-2024-3657: DOS via via specially crafted kerberos AS-REQ request. (bsc#1225512)
- CVE-2024-5953: Malformed userPassword hashes may cause a denial of service. (bsc#1226277)
- CVE-2024-2199: Malformed userPassword may cause crash at do_modify in slapd/modify.c. (bsc#1225507)
</description>
</patchinfo>