PT-2011-1104 · Openldap+1 · Openldap+1

Ralf Haferkamp

+1

·

Publicado

2011-03-10

·

Atualizado

2017-08-17

·

CVE-2011-1081

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.24 OpenLDAP versions 2.4.19 OpenLDAP version 2.4.35 and earlier
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. In OpenLDAP 2.4.x before 2.4.24, the modrdn.c in slapd allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request that contains an empty value for the OldDN field.
Recommendations For OpenLDAP versions prior to 2.4.24, update to version 2.4.24 or later. For OpenLDAP versions 2.4.19, update to a version later than 2.4.19. For OpenLDAP version 2.4.35 and earlier, update to version 2.4.35 or later. As a temporary workaround, consider restricting access to the vulnerable modrdn function until a patch is available.

Exploit

Correção

DoS

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06163
BDU:2015-06459
BDU:2015-06460
BDU:2015-06461
BDU:2015-06462
BDU:2015-06463
BDU:2015-06464
BDU:2015-09683
CVE-2011-1081
RHSA-2011:0347
RHSA-2011_0347

Produtos afetados

Openldap
Red Hat