PT-2011-1104 · Openldap+1 · Openldap+1
Ralf Haferkamp
+1
·
Publicado
2011-03-10
·
Atualizado
2017-08-17
·
CVE-2011-1081
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenLDAP versions prior to 2.4.24
OpenLDAP versions 2.4.19
OpenLDAP version 2.4.35 and earlier
Description
The issue affects the confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. In OpenLDAP 2.4.x before 2.4.24, the modrdn.c in slapd allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request that contains an empty value for the OldDN field.
Recommendations
For OpenLDAP versions prior to 2.4.24, update to version 2.4.24 or later.
For OpenLDAP versions 2.4.19, update to a version later than 2.4.19.
For OpenLDAP version 2.4.35 and earlier, update to version 2.4.35 or later.
As a temporary workaround, consider restricting access to the vulnerable
modrdn function until a patch is available.Exploit
Correção
DoS
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openldap
Red Hat