漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
Vulnerability Description
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
389 Directory Server 资源管理错误漏洞
Vulnerability Description
389 Directory Server是389 Directory Server开源的一个高度可用、功能齐全、可靠和安全的LDAP服务器实现。 389 Directory Server存在资源管理错误漏洞,该漏洞源于Content Synchronization持久搜索插件在认证客户端停止读取同步响应时允许无限制的内存增长,可能导致拒绝服务。此外,插件线程生命周期中的竞争条件可能在连接断开或关闭时导致崩溃。
CVSS Information
N/A
Vulnerability Type
N/A