Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2024:3843-1 — 389-ds (CVE-2024-2199 +2 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for 389-ds

This update for 389-ds fixes the following issues:

  • Persist extracted key path for ldap_ssl_client_init over repeat invocations (bsc#1230852)
  • Re-enable use of .dsrc basedn for dsidm commands (bsc#1231462)
  • Update to version 2.2.10~git18.20ce9289:
  • RFE: Use previously extracted key path
  • Update dsidm to prioritize basedn from .dsrc over interactive input
  • UI: Instance fails to load when DB backup directory doesn't exist
  • Improve online import robustness when the server is under load
  • Ensure all slapi_log_err calls end format strings with newline character \n
  • RFE: when memberof is enabled, defer updates of members from the update of the group
  • Provide more information in the error message during setup_ol_tls_conn()
  • Wrong set of entries returned for some search filters
  • Schema lib389 object is not keeping custom schema data upon editing
  • UI: Fix audit issue with npm - micromatch
  • Fix long delay when setting replication agreement with dsconf
  • Changelog trims updates from a given RID even if a consumer has not received any of them
  • test_password_modify_non_utf8 should set default password storage scheme
  • Update Cargo.lock
  • Rearrange includes for 32-bit support logic
  • Fix fedora cop RawHide builds
  • Bump braces from 3.0.2 to 3.0.3 in /src/cockpit/389-console
  • Enabling replication for a sub suffix crashes browser
  • d2entry - Could not open id2entry err 0 - at startup when having sub-suffixes
  • Slow ldif2db import on a newly created BDB backend
  • Audit log buffering doesn't handle large updates
  • RFE: improve the performance of evaluation of filter component when tested against a large valueset (like group members)
  • passwordHistory is not updated with a pre-hashed password
  • ns-slapd crash in referint_get_config
  • Fix the UTC offset print
  • Fix OpenLDAP version autodetection
  • RFE: add new operation note for MFA authentications
  • Add log buffering to audit log
  • Fix connection timeout error breaking errormap
  • Improve dsidm CLI No Such Entry handling
  • Improve connection timeout error logging
  • Add hidden -v and -j options to each CLI subcommand
  • Fix various issues with logconv.pl
  • Fix certificate lifetime displayed as NaN
  • Enhance Rust and JS bundling and add SPDX licenses for both
  • Remove audit-ci from dependencies
  • Fix unused variable warning from previous commit
  • covscan: fix memory leak in audit log when adding entries
  • Add a check for tagged commits
  • dscreate ds-root - accepts relative path
  • Change replica_id from str to int
  • Attribute Names changed to lowercase after adding the Attributes
  • ns-slapd crashes at startup if a backend has no suffix
  • During an update, if the target entry is reverted in the entry cache, the server should not retry to lock it
  • Reversion of the entry cache should be limited to BETXN plugin failures
  • Disable Transparent Huge Pages
  • Freelist ordering causes high wtime
  • Security fix for CVE-2024-2199
  • VUL-0: CVE-2024-3657: 389-ds: potential denial of service via specially crafted kerberos AS-REQ request (bsc#1225512)
  • VUL-0: CVE-2024-5953: 389-ds: malformed userPassword hashes may cause a denial of service (bsc#1226277)
  • 389ds crash when user does change password using iso-8859-1 encoding (bsc#1228912)

Affected software

SUSE-SU-2024:3843-1 is recorded against 1 package.

  • 389-ds (fixed in 2.2.10~git18.20ce9289-150500.3.24.1)

Timeline and source

Published on 31 October 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-10-31
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
389-ds 2.2.10~git18.20ce9289-150500.3.24.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:3843-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:3843-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.