PT-2010-5626 · Openldap+1 · Libldap2-Dev+7

Published

1970-01-01

·

Updated

2018-10-10

·

CVE-2010-0212

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.35 ldap-utils (affected versions not specified) slapd (affected versions not specified) libldap-2.4-2 (affected versions not specified) libldap-2.4-2-dbg (affected versions not specified) slapd-dbg (affected versions not specified) libldap2-dev (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, potentially leading to disruption of protected information. This can be achieved through exploitation of multiple vulnerabilities in the affected packages, including a modrdn call with a zero-length RDN destination string, which triggers a NULL pointer dereference in the IA5StringNormalize function. The smr normalize function and IA5StringNormalize function in schema init.c are involved in the vulnerability. The exploitation can be performed remotely.
Recommendations For OpenLDAP versions prior to 2.4.35, update to version 2.4.35 or later to resolve the issue. For ldap-utils, slapd, libldap-2.4-2, libldap-2.4-2-dbg, slapd-dbg, and libldap2-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Certificate Validation

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01319
BDU:2015-01321
BDU:2015-02576
BDU:2015-02577
BDU:2015-02578
BDU:2015-02579
BDU:2015-09683
CVE-2010-0212
DSA-2077-1
RHSA-2010:0542
RHSA-2010_0542

Affected Products

Openldap
Red Hat
Ldap-Utils
Libldap-2.4-2
Libldap-2.4-2-Dbg
Libldap2-Dev
Slapd
Slapd-Dbg