The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openldap | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Jul 28, 2010 |
| Centos_linux | — | Upgrade openldap-develUpgrade openldap-servers-overlaysUpgrade openldap-servers-sqlUpgrade compat-openldapUpgrade openldap-serversUpgrade openldap-clientsUpgrade openldap | Dec 1, 2016 | Jul 28, 2010 |
| Debian | — | Upgrade openldap | Jul 30, 2024 | Jul 28, 2010 |
| Gentoo Linux | — | Upgrade net-nds/openldap. | Oct 30, 2017 | Jul 28, 2010 |
| Oracle_linux | — | Upgrade openldap-servers-sqlUpgrade openldapUpgrade openldap-develUpgrade openldap-servers-overlaysUpgrade openldap-serversUpgrade openldap-clientsUpgrade compat-openldap | Oct 16, 2024 | Jul 27, 2010 |
| Suse | — | Upgrade openldap2Upgrade libldap-2_4-2-x86Upgrade libldap-2_4-2Upgrade openldap2-back-metaUpgrade openldap2-clientUpgrade libldap-2_4-2-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade slapd | Nov 8, 2024 | Jul 28, 2010 |
| Vmsa 2011 0001 | — | Upgrade VMware ESX 4.0 to build number 332073 | Jan 5, 2011 | Jul 28, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub