PT-2005-3291 · Nss Ldap · Nss Ldap
Publicado
2005-07-26
·
Atualizado
2017-07-11
·
CVE-2005-2377
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
nss ldap versions 181 through 212
Description
The issue is related to the handling of a SIGPIPE signal when sending a search request to an LDAP directory server. This might allow remote attackers to cause a denial of service, potentially leading to application crashes, if they can cause an LDAP server to become unavailable.
Recommendations
For nss ldap versions 181 through 212, consider implementing signal handling mechanisms to prevent application crashes when an LDAP server becomes unavailable. As a temporary workaround, restrict access to the LDAP directory server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nss Ldap