PT-2020-7744 · Openldap+2 · Openldap+2
Victor Pereira
·
Published
2015-11-19
·
Updated
2020-01-09
·
CVE-2014-8182
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
openldap version 2.4
Description
An off-by-one error was found in openldap when processing DNS SRV messages, potentially leading to a crash. This issue affects configurations using the dnssrv backend, where an attacker could exploit the service with crafted DNS responses, causing it to crash.
Recommendations
For openldap version 2.4, as a temporary workaround, consider disabling the dnssrv backend until a patch is available. Restrict access to the service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Openldap