QSearchQSearch

CVE-2026-11793

4.9 MEDIUM

A stack buffer overflow flaw was found in 389 Directory Server

Published: 2026-06-09 · Last updated: 2026-06-09

Severity and scoring

CVSS
4.9 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-121

Description

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-49760 Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow
  • CVE-2026-49759 Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by...
  • CVE-2026-26241 A buffer overflow vulnerability has been reported to affect File Station 5
  • CVE-2026-26240 A buffer overflow vulnerability has been reported to affect File Station 5
  • CVE-2026-26239 A buffer overflow vulnerability has been reported to affect File Station 5