{"api_version":"1","generated_at":"2026-07-23T12:25:31+00:00","cve":"CVE-2013-4449","urls":{"html":"https://cve.report/CVE-2013-4449","api":"https://cve.report/api/cve/CVE-2013-4449.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-4449","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-4449"},"summary":{"title":"CVE-2013-4449","description":"The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.","state":"PUBLISHED","assigner":"redhat","published_at":"2014-02-05 18:55:06","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:026","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:026","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2014:026 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","name":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle VM Server for x86 Bulletin - July 2016","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.openldap.org/its/index.cgi/Incoming?id=7723","name":"http://www.openldap.org/its/index.cgi/Incoming?id=7723","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenLDAP ITS - Incoming/7723","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-4449","name":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-4449","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Unified Communications Manager Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2013/10/19/3","name":"http://www.openwall.com/lists/oss-security/2013/10/19/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request: slapd segfaults on certain queries\n with rwm overlay enabled","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029711","name":"http://www.securitytracker.com/id/1029711","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenLDAP RWM Overlay Reference Counting Flaw Lets Remote Users Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3209","name":"http://www.debian.org/security/2015/dsa-3209","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3209-1 openldap","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/63190","name":"http://www.securityfocus.com/bid/63190","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenLDAP 'rwm_conn_destroy' Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1019490","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1019490","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 1019490 – CVE-2013-4449 openldap: segfault on certain queries with rwm overlay","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Dec/23","name":"https://seclists.org/bugtraq/2019/Dec/23","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugtraq: APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT210788","name":"https://support.apple.com/kb/HT210788","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"2016-04 Security Bulletin: CTP Series: Multiple vulnerabilities in CTP Series - Juniper Networks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0206.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0206.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/Dec/26","name":"http://seclists.org/fulldisclosure/2019/Dec/26","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Full Disclosure: APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0126.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0126.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-4449","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4449","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.24","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.26","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.28","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.29","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4449","vulnerable":"1","versionEndIncluding":"2.4.36","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"4449","cve":"CVE-2013-4449","epss":"0.687470000","percentile":"0.986360000","score_date":"2026-05-04","updated_at":"2026-05-05 00:07:32"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:45:14.585Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openldap.org/its/index.cgi/Incoming?id=7723"},{"name":"MDVSA-2014:026","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:026"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1019490"},{"name":"DSA-3209","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3209"},{"name":"RHSA-2014:0126","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0126.html"},{"name":"[oss-security] 20131018 Re: CVE request: slapd segfaults on certain queries with rwm overlay enabled","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2013/10/19/3"},{"name":"RHSA-2014:0206","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0206.html"},{"name":"63190","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/63190"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"name":"1029711","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029711"},{"name":"20140401 Cisco Unified Communications Manager Denial of Service Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-4449"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT210788"},{"name":"20191211 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"https://seclists.org/bugtraq/2019/Dec/23"},{"name":"20191213 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2019/Dec/26"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-12-13T20:06:10.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openldap.org/its/index.cgi/Incoming?id=7723"},{"name":"MDVSA-2014:026","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2014:026"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1019490"},{"name":"DSA-3209","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3209"},{"name":"RHSA-2014:0126","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0126.html"},{"name":"[oss-security] 20131018 Re: CVE request: slapd segfaults on certain queries with rwm overlay enabled","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2013/10/19/3"},{"name":"RHSA-2014:0206","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0206.html"},{"name":"63190","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/63190"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"name":"1029711","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029711"},{"name":"20140401 Cisco Unified Communications Manager Denial of Service Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-4449"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT210788"},{"name":"20191211 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"https://seclists.org/bugtraq/2019/Dec/23"},{"name":"20191213 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2019/Dec/26"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-4449","datePublished":"2014-02-05T18:00:00.000Z","dateReserved":"2013-06-12T00:00:00.000Z","dateUpdated":"2024-08-06T16:45:14.585Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-02-05 18:55:06","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*","versionEndIncluding":"2.4.36","matchCriteriaId":"C8A79462-B8A3-4822-A496-AE2A71F706DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*","matchCriteriaId":"5EC66226-A597-4A4C-932F-F4A7BAE119C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*","matchCriteriaId":"4AEABC84-7B67-4FD4-A891-E52C80DC881E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*","matchCriteriaId":"340F673A-295E-4B75-A9D1-E785B0440BE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*","matchCriteriaId":"49203E99-71E2-49D4-91A0-65AAAA7DC18F"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*","matchCriteriaId":"473AEC48-FBBF-4BEB-8728-1FA80DD94807"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*","matchCriteriaId":"7B0415EA-5F21-44C3-93F3-DDADBAA64449"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*","matchCriteriaId":"16AFC655-E81F-4FDE-8030-9781A8B79E73"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*","matchCriteriaId":"E99FB859-D023-4B2B-A709-05E83A46E2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*","matchCriteriaId":"8D2EEBC7-1FAF-43E2-A124-C387C02D9E2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*","matchCriteriaId":"95D242E4-D5EB-4785-A6EF-60B1E8E2B0EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*","matchCriteriaId":"F6FEDD9C-FDF7-456A-B06C-0A4A4443991D"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*","matchCriteriaId":"9245CDE2-B90A-4D47-BA20-A7869FF0A645"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*","matchCriteriaId":"FB993E4D-E573-4495-97DE-465DDB2AA2DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*","matchCriteriaId":"D0F106A3-63D5-4D07-9440-6628DBA78BE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*","matchCriteriaId":"36CC03BC-DF34-43CD-90B0-27D23A1DD06A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*","matchCriteriaId":"16C90FEE-527E-47F5-8840-517A55163D8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*","matchCriteriaId":"0FAEA812-BB47-47A3-A975-B3B8D30DBA36"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*","matchCriteriaId":"5DE5D180-3972-40A0-ADAF-A4F3364D1381"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.24:*:*:*:*:*:*:*","matchCriteriaId":"AD76F376-00D8-4917-BF68-6EECC316C331"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.25:*:*:*:*:*:*:*","matchCriteriaId":"F7063C11-3BF5-4037-ADC3-0C7E9AF830B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.26:*:*:*:*:*:*:*","matchCriteriaId":"CAE258EA-1B57-4189-AD5A-7E2ACF223167"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.27:*:*:*:*:*:*:*","matchCriteriaId":"C492F5F5-A6FD-4BED-890A-79254138CC0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.28:*:*:*:*:*:*:*","matchCriteriaId":"A6F7FDE8-2E54-4162-AA5F-D81253AAC8FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.29:*:*:*:*:*:*:*","matchCriteriaId":"693E3145-FDDB-4780-886B-6D7FC7B2C5B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.30:*:*:*:*:*:*:*","matchCriteriaId":"1BF32056-CC6A-4B2B-8FAA-F573445B9B99"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.31:*:*:*:*:*:*:*","matchCriteriaId":"93B99338-4A1A-4483-8308-49BCCB325C30"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.32:*:*:*:*:*:*:*","matchCriteriaId":"FE652CE3-E16B-4062-8253-F3FB52A651EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.33:*:*:*:*:*:*:*","matchCriteriaId":"2A30ED6D-1DB8-4563-B131-1532F97F9694"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.34:*:*:*:*:*:*:*","matchCriteriaId":"7764366D-29BB-4D75-A33C-7C17DA7496DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.35:*:*:*:*:*:*:*","matchCriteriaId":"0A38D99B-370E-430A-A657-CD9FF72D0863"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"4449","Ordinal":"1","Title":"CVE-2013-4449","CVE":"CVE-2013-4449","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"4449","Ordinal":"1","NoteData":"The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.","Type":"Description","Title":"CVE-2013-4449"},{"CveYear":"2013","CveId":"4449","Ordinal":"2","NoteData":"2014-02-05","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"4449","Ordinal":"3","NoteData":"2019-12-13","Type":"Other","Title":"Modified"}]}}}