OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
BID:52404
Info
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
| Bugtraq ID: | 52404 |
| Class: | Unknown |
| CVE: |
CVE-2012-1164 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 29 2012 12:00AM |
| Updated: | Jul 15 2015 12:16AM |
| Credit: | Mattias Andersson |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6 OpenLDAP OpenLDAP 2.4.29 OpenLDAP OpenLDAP 2.4.23 OpenLDAP OpenLDAP 2.4.22 OpenLDAP OpenLDAP 2.4.3 OpenLDAP OpenLDAP 2.4.2 OpenLDAP OpenLDAP 2.4.1 OpenLDAP OpenLDAP 2.4 OpenLDAP OpenLDAP 2.3.41 OpenLDAP OpenLDAP 2.3.40 OpenLDAP OpenLDAP 2.3.39 OpenLDAP OpenLDAP 2.3.27 OpenLDAP OpenLDAP 2.3.25 OpenLDAP OpenLDAP 2.3.6 OpenLDAP OpenLDAP 2.4.24 OpenLDAP OpenLDAP 2.3.28-E1.0.0 OpenLDAP OpenLDAP 2.3.28-20061022 OpenLDAP OpenLDAP 2.3.28-2.20061022 OpenLDAP OpenLDAP 2.3.27-2.20061018 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: |
OpenLDAP OpenLDAP 2.4.30 |
Discussion
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
OpenLDAP is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to deny service to legitimate users by crashing affected 'slapd' servers.
OpenLDAP is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to deny service to legitimate users by crashing affected 'slapd' servers.
Exploit / POC
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
Attackers use readily available network utilities to exploit this vulnerability.
Attackers use readily available network utilities to exploit this vulnerability.
Solution / Fix
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability
References:
References: