#VU123263 Heap-based buffer overflow in 389-ds-base - CVE-2025-14905
Published: February 25, 2026
389-ds-base
389 Directory Server Project
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the schema_attr_enum_callback() function in ldap/servers/slapd/schema.c. A remote user can send specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.