FreeBSD : 389-ds-base -- multiple vulnerabilities (3f5c81ae-b227-11f1-a655-3497f65b111b)

critical Nessus Plugin ID 346907

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 3f5c81ae-b227-11f1-a655-3497f65b111b advisory.

The 389 Directory Server project reports:
CVE-2026-11770: the replication extended operations did not verify that the bind DN is accepted by the replica, and the CleanRUV status filters were open to LDAP injection.
CVE-2026-18355: a missing minimum length check in sasl_io_start_packet() lets an authenticated SASL user trigger an unsigned integer underflow, causing heap corruption and a crash of the server.
CVE-2026-18453: op_shared_search() does not check for a NULL backend pointer when reusing a paged results slot, so an unauthenticated client can crash ns-slapd with two search requests on one connection. Paged results and anonymous access are enabled by default.
CVE-2026-18922: a failed one-shot SASL exchange leaves stale identity data in the auxprop context, so a later successful bind on the same connection can inherit it and escalate to Directory Manager.
CVE-2026-19843: the cockpit LDAP editor passed the entry DN into a shell command line, so a user who can create or rename an entry can have the host run commands as root when an administrator opens that entry.
CVE-2026-76560: anonymous clients could satisfy SELFDN, USERDNATTR and LDAPURL ACL bind rules, granting unauthorized access.

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/cve/CVE-2026-11770

https://access.redhat.com/security/cve/CVE-2026-18355

https://access.redhat.com/security/cve/CVE-2026-18453

https://access.redhat.com/security/cve/CVE-2026-18922

https://access.redhat.com/security/cve/CVE-2026-19843

https://access.redhat.com/security/cve/CVE-2026-76560

https://github.com/389ds/389-ds-base/releases/tag/389-ds-base-3.2.3

http://www.nessus.org/u?15691c97

Plugin Details

Severity: Critical

ID: 346907

File Name: freebsd_pkg_3f5c81aeb22711f1a6553497f65b111b.nasl

Version: 1.1

Type: Local

Published: 9/17/2026

Updated: 9/17/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.6

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-18922

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:389-ds-base

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 9/17/2026

Vulnerability Publication Date: 7/2/2026

Reference Information

CVE: CVE-2026-11770, CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, CVE-2026-76560