CVE-2018-14648: Debian Linux

High severity, CVSS 7.5. EPSS: 6.3% chance of exploitation in the next 30 days.

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject 389 Directory Server: before 1.4.0.17 (fixed in 1.4.0.17)
  • Red Hat Enterprise Linux: version 7.0 only

Published 2018-09-28. Last modified 2026-06-17.