The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openldap | Aug 30, 2017 | Feb 12, 2015 |
| Apple Osx Adminframework | — | Apply OS X security update 2015-004Upgrade macOS to the latest version | Aug 28, 2015 | Feb 12, 2015 |
| Apple Osx Openldap | — | Apply Apple macOS Security Update 2019-002 MojaveApply Apple macOS Security Update 2019-007 High Sierra | Dec 10, 2019 | Dec 10, 2019 |
| Debian | — | Upgrade openldap | Jul 30, 2024 | Feb 12, 2015 |
| Oracle Solaris | — | Upgrade library/openldap to version 2.4.30-0.175.2.13.0.6.0 on Solaris 11.2 | May 29, 2017 | Feb 12, 2015 |
| Suse | — | Upgrade openldap2-devel-staticUpgrade libldap-openssl1-2_4-2-32bitUpgrade libldap-2_4-2Upgrade libldap-2_4-2-x86Upgrade compat-libldap-2_3-0Upgrade libldap-openssl1-2_4-2Upgrade openldap2-ppolicy-check-passwordUpgrade openldap2-back-metaUpgrade openldap2-develUpgrade openldap2Upgrade libldap-dataUpgrade openldap2-docUpgrade libldap-openssl1-2_4-2-x86Upgrade openldap2-back-perlUpgrade libldap-2_4-2-32bitUpgrade openldap2-clientUpgrade openldap2-devel-32bit | Dec 18, 2015 | Feb 12, 2015 |
| Ubuntu | — | Upgrade slapd | Nov 8, 2024 | Feb 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub