RULE(RULE ID:2105172)

Rule General Information
Release Date: 2018-10-15
Rule Name: Red Hat 389 Directory Server do_search Denial of Service Vulnerability (CVE-2018-14648)
Severity:
CVE ID:
Rule Protection Details
Description: A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14648
https://vuldb.com/?id.124587
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.