CVE-2015-1545
Summary
| CVE | CVE-2015-1545 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-12 16:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openldap | Openldap | 2.4.13 | All | All | All |
| Application | Openldap | Openldap | 2.4.14 | All | All | All |
| Application | Openldap | Openldap | 2.4.15 | All | All | All |
| Application | Openldap | Openldap | 2.4.16 | All | All | All |
| Application | Openldap | Openldap | 2.4.17 | All | All | All |
| Application | Openldap | Openldap | 2.4.18 | All | All | All |
| Application | Openldap | Openldap | 2.4.19 | All | All | All |
| Application | Openldap | Openldap | 2.4.20 | All | All | All |
| Application | Openldap | Openldap | 2.4.21 | All | All | All |
| Application | Openldap | Openldap | 2.4.22 | All | All | All |
| Application | Openldap | Openldap | 2.4.23 | All | All | All |
| Application | Openldap | Openldap | 2.4.24 | All | All | All |
| Application | Openldap | Openldap | 2.4.25 | All | All | All |
| Application | Openldap | Openldap | 2.4.26 | All | All | All |
| Application | Openldap | Openldap | 2.4.27 | All | All | All |
| Application | Openldap | Openldap | 2.4.28 | All | All | All |
| Application | Openldap | Openldap | 2.4.29 | All | All | All |
| Application | Openldap | Openldap | 2.4.30 | All | All | All |
| Application | Openldap | Openldap | 2.4.31 | All | All | All |
| Application | Openldap | Openldap | 2.4.32 | All | All | All |
| Application | Openldap | Openldap | 2.4.33 | All | All | All |
| Application | Openldap | Openldap | 2.4.34 | All | All | All |
| Application | Openldap | Openldap | 2.4.35 | All | All | All |
| Application | Openldap | Openldap | 2.4.36 | All | All | All |
| Application | Openldap | Openldap | 2.4.37 | All | All | All |
| Application | Openldap | Openldap | 2.4.38 | All | All | All |
| Application | Openldap | Openldap | 2.4.39 | All | All | All |
| Application | Openldap | Openldap | 2.4.40 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Support / Security / Advisories / / MDVSA-2015:074 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support / Security / Advisories / / MDVSA-2015:073 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| OpenLDAP Null Pointer Dereference in deref_parseCtrl() Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| APPLE-SA-2015-04-08-2 OS X 10.10.3 and Security Update 2015-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| openSUSE-SU-2015:1325-1: moderate: Security update for openldap2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| OpenLDAP ITS - Message 8027 | af854a3a-2127-422b-91ae-364da2661108 | www.openldap.org | Exploit, Vendor Advisory |
| oss-security - Re: CVE request: two OpenLDAP DoS issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| OpenLDAP slapd Multiple Denial of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Oracle Solaris Third Party Bulletin - July 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Debian -- Security Information -- DSA-3209-1 openldap | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| #776988 - openldap: CVE-2015-1545: crashes on search with deref control and empty attr list - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Projects · Explore · GitLab | af854a3a-2127-422b-91ae-364da2661108 | www.openldap.org | |
| Bugtraq: APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Full Disclosure: APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Projects · Explore · GitLab | MITRE | www.openldap.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| openldap.org | 2015-02-25 | openldap.org | Note that the deref overlay is not enabled by default, so this vulnerability only affects sites that have explicitly configured their servers to load and enable the overlay. Since this overlay has never been documented, there are no sites outside of the OpenLDAP developer community with a legitimate reason to enable this module. |
There are currently no legacy QID mappings associated with this CVE.