A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.
History

Tue, 18 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.
First Time appeared Redhat
Redhat directory Server
Redhat enterprise Linux
CPEs cpe:/a:redhat:directory_server:11
cpe:/a:redhat:directory_server:12
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat directory Server
Redhat enterprise Linux
References

Tue, 18 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title 389-ds-base: null pointer dereference leads to denial of service
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-03-18T16:25:43.712Z

Updated: 2025-03-18T17:48:16.354Z

Reserved: 2025-03-18T02:33:34.463Z

Link: CVE-2025-2487

cve-icon Vulnrichment

Updated: 2025-03-18T17:48:07.711Z

cve-icon NVD

Status : Received

Published: 2025-03-18T17:15:48.883

Modified: 2025-03-18T17:15:48.883

Link: CVE-2025-2487

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-18T00:00:00Z

Links: CVE-2025-2487 - Bugzilla