PT-2006-1055 · Openldap · Openldap

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2754

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OpenLDAP versions prior to 2.3.22
Description: The issue is related to a stack-based buffer overflow in the st.c file of slurpd for OpenLDAP. This could potentially allow attackers to execute arbitrary code via a long hostname. The vulnerability might be exploited remotely, leading to a breach of protected information integrity.
Recommendations: For OpenLDAP versions prior to 2.3.22, update to version 2.3.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the slurpd service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09514
CVE-2006-2754

Affected Products

Openldap