CVE-2015-1545

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
References
Link Resource
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html
http://seclists.org/fulldisclosure/2019/Dec/26
http://secunia.com/advisories/62787
http://www.debian.org/security/2015/dsa-3209
http://www.mandriva.com/security/advisories?name=MDVSA-2015:073
http://www.mandriva.com/security/advisories?name=MDVSA-2015:074
http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=c32e74763f77675b9e144126e375977ed6dc562c
http://www.openldap.org/its/?findid=8027 Exploit Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/02/07/3
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://www.securityfocus.com/bid/72519
http://www.securitytracker.com/id/1032399
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776988
https://exchange.xforce.ibmcloud.com/vulnerabilities/100937
https://seclists.org/bugtraq/2019/Dec/23
https://support.apple.com/HT204659
https://support.apple.com/kb/HT210788
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html
http://seclists.org/fulldisclosure/2019/Dec/26
http://secunia.com/advisories/62787
http://www.debian.org/security/2015/dsa-3209
http://www.mandriva.com/security/advisories?name=MDVSA-2015:073
http://www.mandriva.com/security/advisories?name=MDVSA-2015:074
http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=c32e74763f77675b9e144126e375977ed6dc562c
http://www.openldap.org/its/?findid=8027 Exploit Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/02/07/3
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://www.securityfocus.com/bid/72519
http://www.securitytracker.com/id/1032399
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776988
https://exchange.xforce.ibmcloud.com/vulnerabilities/100937
https://seclists.org/bugtraq/2019/Dec/23
https://support.apple.com/HT204659
https://support.apple.com/kb/HT210788
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.24:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.25:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.26:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.27:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.28:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.29:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.30:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.31:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.32:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.33:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.34:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.35:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.36:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.37:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.38:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.39:*:*:*:*:*:*:*
cpe:2.3:a:openldap:openldap:2.4.40:*:*:*:*:*:*:*

History

21 Nov 2024, 02:25

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html - () http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html -
References () http://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html - () http://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html -
References () http://seclists.org/fulldisclosure/2019/Dec/26 - () http://seclists.org/fulldisclosure/2019/Dec/26 -
References () http://secunia.com/advisories/62787 - () http://secunia.com/advisories/62787 -
References () http://www.debian.org/security/2015/dsa-3209 - () http://www.debian.org/security/2015/dsa-3209 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2015:073 - () http://www.mandriva.com/security/advisories?name=MDVSA-2015:073 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2015:074 - () http://www.mandriva.com/security/advisories?name=MDVSA-2015:074 -
References () http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=c32e74763f77675b9e144126e375977ed6dc562c - () http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=c32e74763f77675b9e144126e375977ed6dc562c -
References () http://www.openldap.org/its/?findid=8027 - Exploit, Vendor Advisory () http://www.openldap.org/its/?findid=8027 - Exploit, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2015/02/07/3 - () http://www.openwall.com/lists/oss-security/2015/02/07/3 -
References () http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html - () http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html -
References () http://www.securityfocus.com/bid/72519 - () http://www.securityfocus.com/bid/72519 -
References () http://www.securitytracker.com/id/1032399 - () http://www.securitytracker.com/id/1032399 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776988 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776988 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/100937 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/100937 -
References () https://seclists.org/bugtraq/2019/Dec/23 - () https://seclists.org/bugtraq/2019/Dec/23 -
References () https://support.apple.com/HT204659 - () https://support.apple.com/HT204659 -
References () https://support.apple.com/kb/HT210788 - () https://support.apple.com/kb/HT210788 -

07 Nov 2023, 02:24

Type Values Removed Values Added
References
  • {'url': 'http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=c32e74763f77675b9e144126e375977ed6dc562c', 'name': 'http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=c32e74763f77675b9e144126e375977ed6dc562c', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=c32e74763f77675b9e144126e375977ed6dc562c -

Information

Published : 2015-02-12 16:59

Updated : 2024-11-21 02:25


NVD link : CVE-2015-1545

Mitre link : CVE-2015-1545

CVE.ORG link : CVE-2015-1545


JSON object : View

Products Affected

openldap

  • openldap