PT-2020-7744 · Openldap+2 · Openldap+2

Victor Pereira

·

Published

2015-11-19

·

Updated

2020-01-09

·

CVE-2014-8182

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions openldap version 2.4
Description An off-by-one error was found in openldap when processing DNS SRV messages, potentially leading to a crash. This issue affects configurations using the dnssrv backend, where an attacker could exploit the service with crafted DNS responses, causing it to crash.
Recommendations For openldap version 2.4, as a temporary workaround, consider disabling the dnssrv backend until a patch is available. Restrict access to the service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_2131
CVE-2014-8182
RHSA-2015:2131
RHSA-2015_2131

Affected Products

Centos
Red Hat
Openldap