PT-2010-5625 · Openldap+1 · Openldap+3

Ilkka Mattila

+1

·

Publicado

1970-01-01

·

Atualizado

2024-01-21

·

CVE-2010-0211

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openldap versions 2.2.13 through 2.4.22 openldap versions prior to 2.4.35 openldap-clients-2.2.13 openldap-servers-2.2.13 openldap-servers-sql-2.2.13 openldap-devel-2.2.13 compat-openldap-2.1.30 libldap-2.4-2 libldap-2.4-2-dbg libldap2-dev slapd slapd-dbg
Description The issue is related to multiple vulnerabilities in the OpenLDAP package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The slap modrdn2mods function in modrdn.c does not check the return value of a call to the smr normalize function, allowing remote attackers to cause a denial of service and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences.
Recommendations For openldap versions 2.2.13 through 2.4.22, update to a version later than 2.4.22. For openldap versions prior to 2.4.35, update to version 2.4.35 or later. For openldap-clients-2.2.13, openldap-servers-2.2.13, openldap-servers-sql-2.2.13, openldap-devel-2.2.13, compat-openldap-2.1.30, libldap-2.4-2, libldap-2.4-2-dbg, libldap2-dev, slapd, and slapd-dbg, update to the latest available version. As a temporary workaround, consider disabling the slap modrdn2mods function until a patch is available. Restrict access to the vulnerable OpenLDAP modules to minimize the risk of exploitation.

Exploit

Correção

DoS

Unchecked Return Value

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01319
BDU:2015-01321
BDU:2015-02576
BDU:2015-02577
BDU:2015-02578
BDU:2015-02579
BDU:2015-06080
BDU:2015-06122
BDU:2015-06123
BDU:2015-06124
BDU:2015-06125
BDU:2015-06126
BDU:2015-08561
BDU:2015-08562
BDU:2015-08563
BDU:2015-08564
BDU:2015-08565
BDU:2015-08566
BDU:2015-09683
CVE-2010-0211
DSA-2077-1
RHSA-2010:0542
RHSA-2010:0543
RHSA-2010_0542
RHSA-2010_0543

Produtos afetados

Openldap
Red Hat
Libldap
Slapd