Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-0212

Опубликовано: 19 июл. 2010
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3openldapAffected
Red Hat Enterprise Linux 4openldapAffected
Red Hat Enterprise Linux 6openldapNot affected
Red Hat Enterprise Linux 5openldapFixedRHSA-2010:054220.07.2010

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=605452openldap: modrdn processing IA5StringNormalize NULL pointer dereference

EPSS

Процентиль: 98%
0.64006
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

nvd
около 15 лет назад

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

debian
около 15 лет назад

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service ( ...

github
больше 3 лет назад

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

oracle-oval
около 15 лет назад

ELSA-2010-0542: openldap security update (MODERATE)

EPSS

Процентиль: 98%
0.64006
Средний

5 Medium

CVSS2