PT-2010-2459 · Sun · Sun Directory Server Enterprise Edition+1

Published

2010-02-25

·

Updated

2017-08-17

·

CVE-2010-0708

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Sun Directory Server Enterprise Edition versions 6.0 through 6.3.1 Sun Java System Directory Server version 5.2 Sun Directory Server Enterprise Edition version 7.0
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash, via a crafted LDAP search request. This can be achieved by exploiting unspecified vulnerabilities in the ns-slapd and slapd.exe components.
Recommendations For Sun Directory Server Enterprise Edition versions 6.0 through 6.3.1, consider restricting access to the LDAP search functionality until a fix is available. For Sun Java System Directory Server version 5.2, avoid using the vulnerable ns-slapd and slapd.exe components in production environments until a patch is released. For Sun Directory Server Enterprise Edition version 7.0, as a temporary workaround, consider disabling the LDAP search functionality to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0708

Affected Products

Sun Directory Server Enterprise Edition
Sun Java System Directory Server