Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-6908

Опубликовано: 11 сент. 2015
Источник: debian
EPSS Высокий

Описание

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openldapfixed2.4.42+dfsg-2package

Примечания

  • http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=6fe51a9ab04fd28bbc171da3cf12f1c1040d6629

  • http://www.openldap.org/its/index.cgi/Software%20Bugs?id=8240;selectid=8240

  • https://www.openwall.com/lists/oss-security/2015/09/11/2

EPSS

Процентиль: 99%
0.73037
Высокий

Связанные уязвимости

ubuntu
почти 10 лет назад

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

redhat
почти 10 лет назад

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

nvd
почти 10 лет назад

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

suse-cvrf
больше 9 лет назад

Security update for openldap2

github
больше 3 лет назад

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

EPSS

Процентиль: 99%
0.73037
Высокий