Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17740

Опубликовано: 20 окт. 2017
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapNot affected
Red Hat Enterprise Linux 5openldap24-libsNot affected
Red Hat Enterprise Linux 6compat-openldapNot affected
Red Hat Enterprise Linux 6openldapNot affected
Red Hat Enterprise Linux 7compat-openldapNot affected
Red Hat Enterprise Linux 7openldapNot affected
Red Hat Enterprise Linux 8openldapNot affected
Red Hat JBoss Core ServicesopenldapNot affected
Red Hat JBoss Enterprise Application Platform 5openldapWill not fix
Red Hat JBoss Enterprise Web Server 2openldapNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-628
https://bugzilla.redhat.com/show_bug.cgi?id=1527076openldap: contrib/slapd-modules/nops/nops.c attempts to free stack buffer allowing remote attackers to cause a denial of service

EPSS

Процентиль: 94%
0.07022
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

CVSS3: 7.5
nvd
больше 8 лет назад

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

CVSS3: 7.5
debian
больше 8 лет назад

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when bot ...

suse-cvrf
больше 7 лет назад

Security update for openldap2

CVSS3: 7.5
github
больше 4 лет назад

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

EPSS

Процентиль: 94%
0.07022
Низкий

5.9 Medium

CVSS3