OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
BID:21560
Info
OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
| Bugtraq ID: | 21560 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2006 12:00AM |
| Updated: | Dec 12 2006 12:00AM |
| Credit: | Solar Eclipse <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
OpenLDAP OpenLDAP 2.4.3 OpenLDAP OpenLDAP 2.4.2 OpenLDAP OpenLDAP 2.4.1 OpenLDAP OpenLDAP 2.4 OpenLDAP OpenLDAP 2.3.25 OpenLDAP OpenLDAP 2.2.29 OpenLDAP OpenLDAP 2.2.15 OpenLDAP OpenLDAP 2.2.6 OpenLDAP OpenLDAP 2.1.30 OpenLDAP OpenLDAP 2.1.25 OpenLDAP OpenLDAP 2.1.22 OpenLDAP OpenLDAP 2.1.19 OpenLDAP OpenLDAP 2.1.18 OpenLDAP OpenLDAP 2.1.17 OpenLDAP OpenLDAP 2.1.16 OpenLDAP OpenLDAP 2.1.15 OpenLDAP OpenLDAP 2.1.14 OpenLDAP OpenLDAP 2.1.13 OpenLDAP OpenLDAP 2.1.12 OpenLDAP OpenLDAP 2.1.11 OpenLDAP OpenLDAP 2.1.10 OpenLDAP OpenLDAP 2.1.4 OpenLDAP OpenLDAP 2.1 .20 OpenLDAP OpenLDAP 2.0.27 OpenLDAP OpenLDAP 2.0.25 OpenLDAP OpenLDAP 2.0.23 OpenLDAP OpenLDAP 2.0.22 OpenLDAP OpenLDAP 2.0.21 OpenLDAP OpenLDAP 2.0.20 OpenLDAP OpenLDAP 2.0.19 OpenLDAP OpenLDAP 2.0.18 OpenLDAP OpenLDAP 2.0.17 OpenLDAP OpenLDAP 2.0.16 OpenLDAP OpenLDAP 2.0.15 OpenLDAP OpenLDAP 2.0.14 OpenLDAP OpenLDAP 2.0.13 OpenLDAP OpenLDAP 2.0.12 OpenLDAP OpenLDAP 2.0.11 -9 OpenLDAP OpenLDAP 2.0.11 -11S OpenLDAP OpenLDAP 2.0.11 -11 OpenLDAP OpenLDAP 2.0.11 OpenLDAP OpenLDAP 2.0.10 OpenLDAP OpenLDAP 2.0.9 OpenLDAP OpenLDAP 2.0.8 OpenLDAP OpenLDAP 2.0.7 OpenLDAP OpenLDAP 2.0.6 OpenLDAP OpenLDAP 2.0.5 OpenLDAP OpenLDAP 2.0.4 OpenLDAP OpenLDAP 2.0.3 OpenLDAP OpenLDAP 2.0.2 OpenLDAP OpenLDAP 2.0.1 OpenLDAP OpenLDAP 2.0 OpenLDAP OpenLDAP 1.2.13 OpenLDAP OpenLDAP 1.2.12 OpenLDAP OpenLDAP 1.2.11 OpenLDAP OpenLDAP 1.2.10 OpenLDAP OpenLDAP 1.2.9 OpenLDAP OpenLDAP 1.2.8 OpenLDAP OpenLDAP 1.2.7 OpenLDAP OpenLDAP 1.2.6 OpenLDAP OpenLDAP 1.2.5 OpenLDAP OpenLDAP 1.2.4 OpenLDAP OpenLDAP 1.2.3 OpenLDAP OpenLDAP 1.2.2 OpenLDAP OpenLDAP 1.2.1 OpenLDAP OpenLDAP 1.2 OpenLDAP OpenLDAP 1.1.4 OpenLDAP OpenLDAP 1.1.3 OpenLDAP OpenLDAP 1.1.2 OpenLDAP OpenLDAP 1.1.1 OpenLDAP OpenLDAP 1.1 OpenLDAP OpenLDAP 1.0.3 OpenLDAP OpenLDAP 1.0.2 OpenLDAP OpenLDAP 1.0.1 OpenLDAP OpenLDAP 1.0 OpenLDAP OpenLDAP 2.3.28-E1.0.0 OpenLDAP OpenLDAP 2.3.28-20061022 OpenLDAP OpenLDAP 2.3.28-2.20061022 OpenLDAP OpenLDAP 2.3.27-2.20061018 |
| Not Vulnerable: | |
Discussion
OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
OpenLDAP server is prone to a remote stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input prior to copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers.
Note that the vulnerable code is not enabled by default; its use has been deprecated for a significant period of time.
OpenLDAP server is prone to a remote stack-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input prior to copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers.
Note that the vulnerable code is not enabled by default; its use has been deprecated for a significant period of time.
Exploit / POC
OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
OpenLDAP Server Kerveros 4 Bind Request Buffer Overflow Vulnerability
References:
References:
- OpenLDAP kbind authentication remote exploit (Solar Eclipse)
- OpenLDAP Mozilla NSS default cipher suite always selected : Bugs7285 (OpenLDAP)
- OpenLDAP kbind authentication buffer overflow (Solar Eclipse
)