Описание
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | released | 2.4.23-0ubuntu1 |
hardy | DNE | |
jaunty | released | 2.4.15-1ubuntu3.1 |
karmic | released | 2.4.18-0ubuntu1.1 |
lucid | released | 2.4.21-0ubuntu5.2 |
upstream | released | 2.4.23 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.2.26-5ubuntu2.10 |
devel | DNE | |
hardy | DNE | |
jaunty | DNE | |
karmic | DNE | |
lucid | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | released | 2.4.9-0ubuntu0.8.04.4 |
jaunty | DNE | |
karmic | DNE | |
lucid | DNE | |
upstream | needs-triage |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service ( ...
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
EPSS
5 Medium
CVSS2