PT-2014-2241 · Isc+2 · Bind-Dyndb-Ldap+2

Ronald Van Zantvoort

·

Published

2012-05-21

·

Updated

2014-03-10

·

CVE-2012-2134

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions bind-dyndb-ldap versions prior to 1.1.0rc1
Description The issue arises from the handle connection error function in ldap helper.c, which fails to properly handle LDAP query errors. This can be exploited by remote attackers to cause a denial of service, resulting in an infinite loop and named server hang. The attack can be triggered by including a non-alphabet character in the base DN of an LDAP search DNS query.
Recommendations For versions prior to 1.1.0rc1, update to version 1.1.0rc1 or later to resolve the issue. As a temporary workaround, consider restricting the input allowed in the base DN of LDAP search DNS queries to prevent the inclusion of non-alphabet characters.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0683
CVE-2012-2134
RHSA-2012:0683
RHSA-2012_0683

Affected Products

Centos
Red Hat
Bind-Dyndb-Ldap