← Back

CVE-2010-0211

nvd nist
Published: Jul 28, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

Affected (6)

Products: Openldap: Openldap · Vmware: Esxi · Opensuse: Opensuse · +1 more
Show all products
1 product
Openldap
1 product
Esxi
1 product
Opensuse
2 products
Mac Os X
Mac Os X Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.4.22
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 4.0
Version 4.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
From 10.6.0 to 10.6.5
From 10.6.0 to 10.6.5

References (38)

Source: cret@cert.org
Broken LinkVendor Advisory
Source: cret@cert.org
Broken LinkVendor Advisory
Source: cret@cert.org
Broken LinkVendor Advisory
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Issue Tracking
Source: cret@cert.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cret@cert.org
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: cret@cert.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Broken LinkVendor Advisory
Source: cret@cert.org
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link

Timeline

No history available yet.