CVE Database
/

CVE-2010-0211

Back to search

CVE-2010-0211

Published: Jul 27, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

VendorProductVersions

n/a

n/a

affected
n/a

References

1024221
vdb-entry
x_refsource_SECTRACK
GLSA-201406-36
vendor-advisory
x_refsource_GENTOO
ADV-2010-1858
vdb-entry
x_refsource_VUPEN
40677
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2010-11-10-1
vendor-advisory
x_refsource_APPLE
ADV-2010-1849
vdb-entry
x_refsource_VUPEN
41770
vdb-entry
x_refsource_BID
RHSA-2010:0542
vendor-advisory
x_refsource_REDHAT
40687
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2010:014
vendor-advisory
x_refsource_SUSE
RHSA-2010:0543
vendor-advisory
x_refsource_REDHAT
40639
third-party-advisory
x_refsource_SECUNIA
42787
third-party-advisory
x_refsource_SECUNIA
ADV-2011-0025
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2010-0211 - Security Vulnerability | QwikSec