PT-2005-3291 · Nss Ldap · Nss Ldap

Published

2005-07-26

·

Updated

2017-07-11

·

CVE-2005-2377

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions nss ldap versions 181 through 212
Description The issue is related to the handling of a SIGPIPE signal when sending a search request to an LDAP directory server. This might allow remote attackers to cause a denial of service, potentially leading to application crashes, if they can cause an LDAP server to become unavailable.
Recommendations For nss ldap versions 181 through 212, consider implementing signal handling mechanisms to prevent application crashes when an LDAP server becomes unavailable. As a temporary workaround, restrict access to the LDAP directory server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2377

Affected Products

Nss Ldap