OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openldap | — | Apply OS X security update 2010-007Upgrade macOS to the latest version | Dec 16, 2011 | Jul 28, 2010 |
| Centos_linux | — | Upgrade openldapUpgrade openldap-servers-sqlUpgrade openldap-servers-overlaysUpgrade openldap-develUpgrade openldap-clientsUpgrade openldap-serversUpgrade compat-openldap | Dec 1, 2016 | Jul 28, 2010 |
| Debian | — | Upgrade openldap | Jul 30, 2024 | Jul 28, 2010 |
| Gentoo Linux | — | Upgrade net-nds/openldap. | Oct 30, 2017 | Jul 28, 2010 |
| Oracle_linux | — | Upgrade openldapUpgrade compat-openldapUpgrade openldap-clientsUpgrade openldap-develUpgrade openldap-servers-sqlUpgrade openldap-serversUpgrade openldap-servers-overlays | Oct 16, 2024 | Jul 27, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 19, 2010 |
| Suse | — | Upgrade openldap2Upgrade libldap-2_4-2-32bitUpgrade libldap-2_4-2Upgrade libldap-2_4-2-x86Upgrade openldap2-clientUpgrade openldap2-back-meta | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade slapd | Nov 8, 2024 | Jul 28, 2010 |
| Vmsa 2011 0001 | — | Upgrade VMware ESX 4.0 to build number 332073 | Jan 5, 2011 | Jul 28, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub