Bug 1083689 - (CVE-2018-1054) VUL-0: CVE-2018-1054: 389-ds: Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c
(CVE-2018-1054)
VUL-0: CVE-2018-1054: 389-ds: Denial of Service (DoS) via search filters in S...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE Factory
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
CVSSv3:RedHat:CVE-2018-1054:7.5:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-03-02 11:20 UTC by Johannes Segitz
Modified: 2020-04-11 22:50 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-03-02 11:20:29 UTC
Created attachment 762483 [details]
Proposed patch

From: Dhiru Kholia via distros

Here is a notification about a remote DoS flaw in the 389-ds-base
package (389 Directory Server).

NOTE: We are planning to make this flaw public on 05-March-2018. If this
date changes, we will inform the list.

A patch to fix this issue is attached to this email.

I am not subscribed to this list. So please CC me if you have some
questions or comments for me.

CVE-2018-1054
-------------

389-ds-base: remote Denial of Service (DoS) via search filters in
SetUnicodeStringFromUTF_8 in collate.c

A flaw was found in 389 Directory Server that affects all versions. An
improper handling of the search feature with an extended filter, when
read access on <attribute_name> is enabled, in SetUnicodeStringFromUTF_8
function in collate.c, can lead to out-of-bounds memory operations. This
may allow a remote unauthenticated attacker to trigger a server crash,
thus resulting in denial of service.

CVSSv3: 7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Comment 2 Johannes Segitz 2018-03-06 07:18:52 UTC
public, please submit
Comment 3 Alexander Bergmann 2018-05-08 07:15:12 UTC
Howard, please submit.
Comment 4 Alexander Bergmann 2019-04-15 15:31:47 UTC
@William: Could you please check the status of this bug?
Comment 5 William Brown 2019-04-16 02:05:16 UTC
An update to 389-ds source to 1.4.0.22 is recommended to resolve this and many other issues.
Comment 10 William Brown 2019-07-31 04:05:32 UTC
Hi,

I'm not clear on why we need an ECO - these submissions have just been upstream-patch releases which are based on the 389-ds enterprise lifecycle support. The project releases minor versions specifically to address issues like this, so that we don't need to carry a large number of .patch files in the rpm.

No features or other elements of the package are changing, so I'm really not clear why an ECO is needed and why this was rejected?

I'm going to re-submit shortly with the latest patch release, as I really do want to get this update process sorted out and working correctly. 

Thanks,
Comment 16 Swamp Workflow Management 2019-08-15 19:13:26 UTC
SUSE-SU-2019:2155-1: An update that solves 8 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1083689,1092187,1099465,1105606,1108674,1109609,1120189,1132385,1144797,991201
CVE References: CVE-2016-5416,CVE-2018-1054,CVE-2018-10871,CVE-2018-1089,CVE-2018-10935,CVE-2018-14638,CVE-2018-14648,CVE-2019-3883
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP1 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Server Applications 15 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Marcus Meissner 2019-10-30 09:29:09 UTC
done
Comment 18 Swamp Workflow Management 2020-04-11 22:50:10 UTC
This is an autogenerated message for OBS integration:
This bug (1083689) was mentioned in
https://build.opensuse.org/request/show/793266 15.1 / 389-ds