Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8182

Опубликовано: 21 июл. 2014
Источник: redhat
CVSS3: 3.7
CVSS2: 2.6
EPSS Низкий

Описание

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

An off-by-one error leading to a crash was discovered in openldap's processing of DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapWill not fix
Red Hat Enterprise Linux 6openldapFixedRHBA-2015:129222.07.2015
Red Hat Enterprise Linux 7openldapFixedRHSA-2015:213119.11.2015

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1095976openldap: crash in ldap_domain2hostlist when processing SRV records

EPSS

Процентиль: 90%
0.05154
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

CVSS3: 7.5
nvd
около 6 лет назад

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

CVSS3: 7.5
debian
около 6 лет назад

An off-by-one error leading to a crash was discovered in openldap 2.4 ...

github
больше 3 лет назад

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

EPSS

Процентиль: 90%
0.05154
Низкий

3.7 Low

CVSS3

2.6 Low

CVSS2