CVE-2024-1062: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Affected products
- Fedoraproject Fedora: version 39 only; version 40 only; version 41 only
- Red Hat 389 Directory Server: before 2.2.0 (fixed in 2.2.0)
- Red Hat Directory Server: affected versions not specified; version 11.7 only; version 11.8 only; version 12.0 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.2 only
- Red Hat Enterprise Linux For Arm 64 Eus: version 8.6 only; version 8.8 only; version 9.2 only
- Red Hat Enterprise Linux For IBM Z Systems: version 9.2 only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.8 only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 8.8 only; version 9.2 only
- Red Hat Enterprise Linux Server Aus: version 8.6 only; version 9.2 only
- Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 8.6 only; version 8.8 only; version 9.2 only
- Red Hat Enterprise Linux Server Tus: version 8.6 only; version 8.8 only
- Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.6 only; version 8.8 only
Published 2024-02-12. Last modified 2026-06-17.