Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1827

Опубликовано: 18 фев. 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.

It was discovered that the IPA extdom Directory Server plug-in did not correctly perform memory reallocation when handling user account information. A request for a list of groups for a user that belongs to a large number of groups would cause a Directory Server to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ipaNot affected
Red Hat Enterprise Linux 7ipaFixedRHSA-2015:072826.03.2015
Red Hat Enterprise Linux 7slapi-nisFixedRHSA-2015:072826.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=1205200ipa: memory corruption when using get_user_grouplist()

EPSS

Процентиль: 78%
0.01175
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.

nvd
больше 10 лет назад

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.

debian
больше 10 лет назад

The get_user_grouplist function in the extdom plug-in in FreeIPA befor ...

github
больше 3 лет назад

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.

oracle-oval
больше 10 лет назад

ELSA-2015-0728: ipa and slapi-nis security and bug fix update (MODERATE)

EPSS

Процентиль: 78%
0.01175
Низкий

5 Medium

CVSS2