← Vulnerability feed

Vulnerability record · CVE-2008-3283 · published 29 August 2008

CVE-2008-3283: Fedora directory server vulnerability

Fedora · Directory Server

Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.

7.8 CVSS 2.0 High EPSS 2.9% · top 13.8% CWE-399 · CWE-399
7.8CVSS 2.0 base score
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
36References
16 Jun 2026Last modified by NVD

Description

Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01532861
http://secunia.com/advisories/31565
http://secunia.com/advisories/31627
http://secunia.com/advisories/31702
http://secunia.com/advisories/31867
http://secunia.com/advisories/31913
http://securitytracker.com/id?1020774
http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html Patch
http://www.redhat.com/support/errata/RHSA-2008-0602.html
http://www.redhat.com/support/errata/RHSA-2008-0858.html
http://www.securityfocus.com/bid/30872 Patch
http://www.vupen.com/english/advisories/2008/2480
https://bugzilla.redhat.com/show_bug.cgi?id=458977
https://exchange.xforce.ibmcloud.com/vulnerabilities/44731
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6118
https://rhn.redhat.com/errata/RHSA-2008-0596.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00521.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00708.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01532861
http://secunia.com/advisories/31565
http://secunia.com/advisories/31627
http://secunia.com/advisories/31702
http://secunia.com/advisories/31867
http://secunia.com/advisories/31913
http://securitytracker.com/id?1020774
http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html Patch
http://www.redhat.com/support/errata/RHSA-2008-0602.html
http://www.redhat.com/support/errata/RHSA-2008-0858.html
http://www.securityfocus.com/bid/30872 Patch
http://www.vupen.com/english/advisories/2008/2480
https://bugzilla.redhat.com/show_bug.cgi?id=458977
https://exchange.xforce.ibmcloud.com/vulnerabilities/44731
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6118
https://rhn.redhat.com/errata/RHSA-2008-0596.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00521.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00708.html

Track CVE-2008-3283 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-2928Redhat directory server memory buffer overflow vulnerabilityMultiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a d…EPSS 6.6%9.0CVE-2008-0892Redhat directory server improper input validation vulnerabilityThe replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allow…EPSS 14%7.5CVE-2026-11770Redhat directory server ldap injection vulnerabilityA flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c…EPSS 0.53%7.5CVE-2026-15722Redhat directory server stack-based buffer overflow vulnerabilityA stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c…EPSS 0.83%7.5CVE-2026-11788Redhat directory server null pointer dereference vulnerabilityA flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…EPSS 0.56%7.5CVE-2026-9064Redhat directory server allocation without limits vulnerabilityA flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont…EPSS 1.1%7.5CVE-2022-1949Redhat 389 directory server insecure direct object reference vulnerabilityAn access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr…EPSS 1.5%7.5CVE-2010-2222Redhat directory server null pointer dereference vulnerabilityThe _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointe…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2008-3283), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.