[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-0212Date: (C)2010-07-28   (M)2024-02-22


OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1024221
http://www.securityfocus.com/archive/1/515545/100/0/threaded
SECUNIA-40639
SECUNIA-40687
BID-41770
SECUNIA-42787
ADV-2010-1849
ADV-2010-1858
ADV-2011-0025
APPLE-SA-2010-11-10-1
GLSA-201406-36
RHSA-2010:0542
SUSE-SR:2010:014
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735
http://support.apple.com/kb/HT4435
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570
http://www.vmware.com/security/advisories/VMSA-2011-0001.html

CPE    1
cpe:/a:openldap:openldap:2.4.22
CWE    1
CWE-264
OVAL    10
oval:org.secpod.oval:def:100405
oval:org.secpod.oval:def:700084
oval:org.secpod.oval:def:201950
oval:org.secpod.oval:def:4714
...

© SecPod Technologies