PT-2006-1055 · Openldap · Openldap
Published
2006-06-01
·
Updated
2018-10-18
·
CVE-2006-2754
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenLDAP versions prior to 2.3.22
Description:
The issue is related to a stack-based buffer overflow in the st.c file of slurpd for OpenLDAP. This could potentially allow attackers to execute arbitrary code via a long hostname. The vulnerability might be exploited remotely, leading to a breach of protected information integrity.
Recommendations:
For OpenLDAP versions prior to 2.3.22, update to version 2.3.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the slurpd service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openldap