CVE-2018-14638: Fedoraproject 389 Directory Server

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.

Affected products

  • Fedoraproject 389 Directory Server: before 1.3.8.4 (fixed in 1.3.8.4)
  • Red Hat Enterprise Linux Aus: version 7.6 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Eus: version 7.5 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-09-14. Last modified 2026-06-17.