View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2019-10171 severity important: SUSE including 5 source package names (389-ds, 389-ds-devel, 389-ds-snmp, lib389, libsvrcore0), 75 product×package rows across 19 product lines (SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, … (19 product lines)): Known Not Affected 75.
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.