LWN.net Logo

openldap: denial of service

Package(s):openldap CVE #(s):CVE-2011-4079
Created:November 17, 2011 Updated:November 23, 2011
Description:

From the Ubuntu advisory:

An OpenLDAP server could potentially be made to crash if it received specially crafted network traffic from an authenticated user.

[...]

It was discovered that slapd contained an off-by-one error. An authenticated attacker could potentially exploit this by sending a crafted crafted LDIF entry containing an empty postalAddress.

Alerts:
Ubuntu USN-1266-1 2011-11-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds