contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openldap | Nov 8, 2019 | Dec 18, 2017 |
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openldap-clientsUpgrade openldap-develUpgrade openldap-serversUpgrade openldap | Feb 26, 2020 | Dec 18, 2017 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Oct 20, 2017 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.1.6Upgrade Splunk Enterprise to version 9.2.3Upgrade Splunk Enterprise to version 9.3.1 | Jul 30, 2026 | Dec 18, 2017 |
| Suse | — | Upgrade openldap2-contribUpgrade openldap2Upgrade openldap2-back-perlUpgrade openldap2-ppolicy-check-passwordUpgrade libldap-dataUpgrade openldap2-devel-32bitUpgrade openldap2-back-sockUpgrade libldap-2_4-2Upgrade openldap2-clientUpgrade openldap2-back-metaUpgrade compat-libldap-2_3-0Upgrade openldap2-back-sqlUpgrade openldap2-devel-staticUpgrade libldap-2_4-2-32bitUpgrade openldap2-docUpgrade openldap2-devel | Dec 18, 2018 | Dec 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub