CVE-2021-3514 log

Source
Severity Low
Remote Yes
Type Denial of service
Description
A security issue was found in 389-ds-base before version 2.0.5. When using a sync_repl client, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash of 389-ds-base.
Group Package Affected Fixed Severity Status Ticket
AVG-2206 389-ds-base 2.0.3-2 2.0.7-1 Medium Fixed
Date Advisory Group Package Severity Type
27 Jul 2021 ASA-202107-72 AVG-2206 389-ds-base Medium multiple issues
References
https://bugzilla.redhat.com/show_bug.cgi?id=1952907
https://github.com/389ds/389-ds-base/issues/4711
https://github.com/389ds/389-ds-base/pull/4738
https://github.com/389ds/389-ds-base/commit/d7eef2fcfbab2ef8aa6ee0bf60f0a9b16ede66e0