Описание
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | released | 2.4.23-0ubuntu1 |
hardy | DNE | |
jaunty | released | 2.4.15-1ubuntu3.1 |
karmic | released | 2.4.18-0ubuntu1.1 |
lucid | released | 2.4.21-0ubuntu5.2 |
upstream | released | 2.4.23 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.2.26-5ubuntu2.10 |
devel | DNE | |
hardy | DNE | |
jaunty | DNE | |
karmic | DNE | |
lucid | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | released | 2.4.9-0ubuntu0.8.04.4 |
jaunty | DNE | |
karmic | DNE | |
lucid | DNE | |
upstream | needs-triage |
Показывать по
EPSS
5 Medium
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not ...
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
EPSS
5 Medium
CVSS2
9.8 Critical
CVSS3