CVE-2019-10171: Fedoraproject 389 Directory Server

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.

Affected products

  • Fedoraproject 389 Directory Server: from 1.4.0.0, before 1.4.0.17 (fixed in 1.4.0.17)
  • Red Hat Enterprise Linux Server Eus: version 7.5 only

Published 2019-08-02. Last modified 2026-06-17.