CVE-2017-15134: Fedoraproject 389 Directory Server

High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

Affected products

  • Fedoraproject 389 Directory Server: from 1.3.6.1, before 1.3.6.13 (fixed in 1.3.6.13); from 1.3.7.1, before 1.3.7.9 (fixed in 1.3.7.9); from 1.4.0.0, before 1.4.0.5 (fixed in 1.4.0.5)
  • Red Hat Enterprise Linux: version 7.4 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only; version 7.4 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-03-01. Last modified 2026-06-17.