CVE-2021-3480

NameCVE-2021-3480
DescriptionA flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs988736

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
slapi-nis (PTS)stretch0.56.1-1vulnerable
buster0.56.2-1vulnerable
bullseye, sid0.56.5-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
slapi-nissource(unstable)0.56.5-2988736

Notes

[bullseye] - slapi-nis <no-dsa> (Minor issue)
[buster] - slapi-nis <no-dsa> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=1944640
https://pagure.io/slapi-nis/c/c7417ea2d534712e559b56ed45baa91c5d3d44db?branch=master

Search for package or bug name: Reporting problems