PT-2010-5625 · Openldap+1 · Openldap+3

Ilkka Mattila

+1

·

Published

1970-01-01

·

Updated

2024-01-21

·

CVE-2010-0211

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openldap versions 2.2.13 through 2.4.22 openldap versions prior to 2.4.35 openldap-clients-2.2.13 openldap-servers-2.2.13 openldap-servers-sql-2.2.13 openldap-devel-2.2.13 compat-openldap-2.1.30 libldap-2.4-2 libldap-2.4-2-dbg libldap2-dev slapd slapd-dbg
Description The issue is related to multiple vulnerabilities in the OpenLDAP package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The slap modrdn2mods function in modrdn.c does not check the return value of a call to the smr normalize function, allowing remote attackers to cause a denial of service and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences.
Recommendations For openldap versions 2.2.13 through 2.4.22, update to a version later than 2.4.22. For openldap versions prior to 2.4.35, update to version 2.4.35 or later. For openldap-clients-2.2.13, openldap-servers-2.2.13, openldap-servers-sql-2.2.13, openldap-devel-2.2.13, compat-openldap-2.1.30, libldap-2.4-2, libldap-2.4-2-dbg, libldap2-dev, slapd, and slapd-dbg, update to the latest available version. As a temporary workaround, consider disabling the slap modrdn2mods function until a patch is available. Restrict access to the vulnerable OpenLDAP modules to minimize the risk of exploitation.

Exploit

Fix

DoS

Unchecked Return Value

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2015-01319
BDU:2015-01321
BDU:2015-02576
BDU:2015-02577
BDU:2015-02578
BDU:2015-02579
BDU:2015-06080
BDU:2015-06122
BDU:2015-06123
BDU:2015-06124
BDU:2015-06125
BDU:2015-06126
BDU:2015-08561
BDU:2015-08562
BDU:2015-08563
BDU:2015-08564
BDU:2015-08565
BDU:2015-08566
BDU:2015-09683
CVE-2010-0211
DSA-2077-1
RHSA-2010:0542
RHSA-2010:0543
RHSA-2010_0542
RHSA-2010_0543

Affected Products

Openldap
Red Hat
Libldap
Slapd