PT-2007-1002 · Openldap+1 · Openldap+1
CVE-2007-5707
·
Publicado
2007-10-30
·
Atualizado
2023-02-13
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
OpenLDAP versions prior to 2.3.39
OpenLDAP version 2.3.27
Description:
The issue allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. This can lead to disruption of protected information and can be exploited remotely.
Recommendations:
For OpenLDAP versions prior to 2.3.39, update to version 2.3.39 or later to resolve the issue.
For OpenLDAP version 2.3.27, consider disabling the LDAP service or restricting access to it until a patch is available.
As a temporary workaround, consider disabling the
objectClasses attribute in LDAP requests until a patch is available.Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openldap
Red Hat