[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-1081Date: (C)2011-03-19   (M)2023-12-22


modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1025191
SECUNIA-43331
SECUNIA-43718
ADV-2011-0665
GLSA-201406-36
MDVSA-2011:055
MDVSA-2011:056
RHSA-2011:0347
USN-1100-1
http://www.openldap.org/lists/openldap-announce/201102/msg00000.html
http://openwall.com/lists/oss-security/2011/02/28/2
http://openwall.com/lists/oss-security/2011/03/01/15
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/modrdn.c.diff?r1=1.170.2.8&r2=1.170.2.9
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6768
https://bugzilla.novell.com/show_bug.cgi?id=674985
https://bugzilla.redhat.com/show_bug.cgi?id=680975
openldap-modrdnc-dos(66239)

CPE    18
cpe:/a:openldap:openldap:2.4.23
cpe:/a:openldap:openldap:2.4.22
cpe:/a:openldap:openldap:2.4.21
cpe:/a:openldap:openldap:2.4.20
...
CWE    1
CWE-399
OVAL    7
oval:org.secpod.oval:def:300428
oval:org.secpod.oval:def:300429
oval:org.secpod.oval:def:500223
oval:org.secpod.oval:def:700277
...

© SecPod Technologies