{"id":"MGASA-2018-0245","summary":"Updated 389-ds-base packages fix security vulnerability","details":"389-ds-base did not properly handle characters needed to be escaped in\nits query filter. This could result in buffer overflows, from the heap\nor the stack, on larger filters.  An unauthenticated attacker could send\na specially crafted LDAP request and crash the server (CVE-2018-1089).\n","modified":"2026-04-16T01:47:01.437801381Z","published":"2018-05-16T08:24:56Z","upstream":["CVE-2018-1089"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0245.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=23005"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1089"}],"affected":[{"package":{"name":"389-ds-base","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5.17-1.5.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0245.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}