A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
| Software | From | Fixed in |
|---|---|---|
| port389 / 389-ds-base | - | 1.3.10.2 |
| redhat / enterprise_linux_workstation | 7.0 | 7.0.x |
| redhat / enterprise_linux_for_scientific_computing | 7.0 | 7.0.x |
| redhat / enterprise_linux_server | 7.0 | 7.0.x |
| redhat / enterprise_linux_for_power_little_endian | 7.0 | 7.0.x |
| redhat / enterprise_linux_for_power_big_endian | 7.0 | 7.0.x |
| redhat / enterprise_linux_for_ibm_z_systems | 7.0 | 7.0.x |
| redhat / enterprise_linux_desktop | 7 | 7.x |