OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
BID:50384
Info
OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 50384 |
| Class: | Design Error |
| CVE: |
CVE-2011-4079 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2011 12:00AM |
| Updated: | Jul 02 2014 12:45AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 OpenLDAP OpenLDAP 2.4.23 OpenLDAP OpenLDAP 2.4.22 OpenLDAP OpenLDAP 2.4.3 OpenLDAP OpenLDAP 2.4.2 OpenLDAP OpenLDAP 2.4.1 OpenLDAP OpenLDAP 2.4 OpenLDAP OpenLDAP 2.3.41 OpenLDAP OpenLDAP 2.3.40 OpenLDAP OpenLDAP 2.3.39 OpenLDAP OpenLDAP 2.3.27 OpenLDAP OpenLDAP 2.3.25 OpenLDAP OpenLDAP 2.3.6 OpenLDAP OpenLDAP 2.2.29 OpenLDAP OpenLDAP 2.2.26 OpenLDAP OpenLDAP 2.2.15 OpenLDAP OpenLDAP 2.2.6 OpenLDAP OpenLDAP 2.1.30 OpenLDAP OpenLDAP 2.1.25 OpenLDAP OpenLDAP 2.1.22 OpenLDAP OpenLDAP 2.1.19 OpenLDAP OpenLDAP 2.1.18 OpenLDAP OpenLDAP 2.1.17 OpenLDAP OpenLDAP 2.1.16 OpenLDAP OpenLDAP 2.1.15 OpenLDAP OpenLDAP 2.1.14 OpenLDAP OpenLDAP 2.1.13 OpenLDAP OpenLDAP 2.1.12 OpenLDAP OpenLDAP 2.1.11 OpenLDAP OpenLDAP 2.1.10 OpenLDAP OpenLDAP 2.1.4 OpenLDAP OpenLDAP 2.1 .20 OpenLDAP OpenLDAP 2.0.27 OpenLDAP OpenLDAP 2.0.25 OpenLDAP OpenLDAP 2.0.23 OpenLDAP OpenLDAP 2.0.22 OpenLDAP OpenLDAP 2.0.21 OpenLDAP OpenLDAP 2.0.20 OpenLDAP OpenLDAP 2.0.19 OpenLDAP OpenLDAP 2.0.18 OpenLDAP OpenLDAP 2.0.17 OpenLDAP OpenLDAP 2.0.16 OpenLDAP OpenLDAP 2.0.15 OpenLDAP OpenLDAP 2.0.14 OpenLDAP OpenLDAP 2.0.13 OpenLDAP OpenLDAP 2.0.12 OpenLDAP OpenLDAP 2.0.11 -9 OpenLDAP OpenLDAP 2.0.11 -11S OpenLDAP OpenLDAP 2.0.11 -11 OpenLDAP OpenLDAP 2.0.11 OpenLDAP OpenLDAP 2.0.10 OpenLDAP OpenLDAP 2.0.9 OpenLDAP OpenLDAP 2.0.8 OpenLDAP OpenLDAP 2.0.7 OpenLDAP OpenLDAP 2.0.6 OpenLDAP OpenLDAP 2.0.5 OpenLDAP OpenLDAP 2.0.4 OpenLDAP OpenLDAP 2.0.3 OpenLDAP OpenLDAP 2.0.2 OpenLDAP OpenLDAP 2.0.1 OpenLDAP OpenLDAP 2.0 OpenLDAP OpenLDAP 2.4.24 OpenLDAP OpenLDAP 2.3.28-E1.0.0 OpenLDAP OpenLDAP 2.3.28-20061022 OpenLDAP OpenLDAP 2.3.28-2.20061022 OpenLDAP OpenLDAP 2.3.27-2.20061018 Gentoo Linux |
| Not Vulnerable: | |
Discussion
OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
OpenLDAP is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to crash the affected application. Arbitrary code execution may also be possible; however, this has not been confirmed.
OpenLDAP is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to crash the affected application. Arbitrary code execution may also be possible; however, this has not been confirmed.
Exploit / POC
OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more
information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more
information, please mail us at: [email protected].
Solution / Fix
OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenLDAP 'UTF8StringNormalize()' Remote Buffer Overflow Vulnerability
References:
References: