CVE-2018-1054: Fedoraproject 389 Directory Server

High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.

An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

Affected products

  • Fedoraproject 389 Directory Server: up to and including 1.4.0.6
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only; version 7.4 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2018-03-07. Last modified 2026-06-17.