slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openldap | Aug 30, 2017 | Jun 29, 2012 |
| Apple Osx Openldap | — | Apply Apple macOS Security Update 2019-002 MojaveApply Apple macOS Security Update 2019-007 High Sierra | Dec 11, 2019 | Dec 10, 2019 |
| Centos_linux | — | Upgrade openldapUpgrade openldap-develUpgrade openldap-clientsUpgrade openldap-serversUpgrade openldap-servers-sql | Dec 1, 2016 | Jun 29, 2012 |
| Debian | — | Upgrade openldap | Jul 30, 2024 | Jun 29, 2012 |
| Gentoo Linux | — | Upgrade net-nds/openldap. | Oct 30, 2017 | Jun 29, 2012 |
| Oracle_linux | — | Upgrade openldap-develUpgrade openldap-servers-sqlUpgrade openldap-clientsUpgrade openldapUpgrade openldap-servers | Oct 16, 2024 | Jun 29, 2012 |
| Suse | — | Upgrade libldap-2_4-2Upgrade libldap-2_4-2-32bitUpgrade openldap2-devel-32bitUpgrade openldap2Upgrade openldap2-develUpgrade libldap-openssl1-2_4-2-32bitUpgrade openldap2-back-metaUpgrade openldap2-clientUpgrade libldap-2_4-2-x86Upgrade libldap-openssl1-2_4-2Upgrade openldap2-back-perlUpgrade compat-libldap-2_3-0 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade slapd | Nov 8, 2024 | Jun 29, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub