Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
| Software | From | Fixed in |
|---|---|---|
| redhat / directory_server | 7.1-sp4 | 7.1-sp4.x |
| redhat / directory_server | 7.1-sp6 | 7.1-sp6.x |
| redhat / directory_server | 7.1-sp2 | 7.1-sp2.x |
| redhat / directory_server | 7.1-sp1 | 7.1-sp1.x |
| redhat / directory_server | 8.0 | 8.0.x |
| fedora / directory_server | 1.1.1 | 1.1.1.x |
| redhat / directory_server | 7.1-sp5 | 7.1-sp5.x |
| redhat / directory_server | 7.1-sp3 | 7.1-sp3.x |