PT-2005-3291 · Nss Ldap · Nss Ldap

Publicado

2005-07-26

·

Atualizado

2017-07-11

·

CVE-2005-2377

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions nss ldap versions 181 through 212
Description The issue is related to the handling of a SIGPIPE signal when sending a search request to an LDAP directory server. This might allow remote attackers to cause a denial of service, potentially leading to application crashes, if they can cause an LDAP server to become unavailable.
Recommendations For nss ldap versions 181 through 212, consider implementing signal handling mechanisms to prevent application crashes when an LDAP server becomes unavailable. As a temporary workaround, restrict access to the LDAP directory server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2377

Produtos afetados

Nss Ldap