← Back

CVE-2011-4079

nvd nist
Published: Oct 27, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:P
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.

Affected (175)

Products: Openldap: Openldap
1 product
Openldap
Configuration A
175 vulnerable
Vulnerable SoftwareAffected Versions
Openldap
Up to 2.4.26
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1
Version 1.2.0
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.13
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9
Version 1.2
Version 2.0.0
Version 2.0.10
Version 2.0.11
Version 2.0.11_11
Version 2.0.11_11s
Version 2.0.11_9
Version 2.0.12
Version 2.0.13
Version 2.0.14
Version 2.0.15
Version 2.0.16
Version 2.0.17
Version 2.0.18
Version 2.0.19
Version 2.0.1
Version 2.0.20
Version 2.0.21
Version 2.0.22
Version 2.0.23
Version 2.0.24
Version 2.0.25
Version 2.0.26
Version 2.0.27
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.0
Version 2.1.10
Version 2.1.11
Version 2.1.12
Version 2.1.13
Version 2.1.14
Version 2.1.15
Version 2.1.16
Version 2.1.17
Version 2.1.18
Version 2.1.19
Version 2.1.20
Version 2.1.21
Version 2.1.22
Version 2.1.23
Version 2.1.24
Version 2.1.25
Version 2.1.26
Version 2.1.27
Version 2.1.28
Version 2.1.29
Version 2.1.2
Version 2.1.30
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1.8
Version 2.1.9
Version 2.1_.20
Version 2.2.0
Version 2.2.10
Version 2.2.11
Version 2.2.12
Version 2.2.13
Version 2.2.14
Version 2.2.15
Version 2.2.16
Version 2.2.17
Version 2.2.18
Version 2.2.19
Version 2.2.1
Version 2.2.20
Version 2.2.21
Version 2.2.22
Version 2.2.23
Version 2.2.24
Version 2.2.25
Version 2.2.26
Version 2.2.27
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.13
Version 2.3.14
Version 2.3.15
Version 2.3.16
Version 2.3.17
Version 2.3.18
Version 2.3.19
Version 2.3.20
Version 2.3.21
Version 2.3.22
Version 2.3.23
Version 2.3.24
Version 2.3.25
Version 2.3.26
Version 2.3.27
Version 2.3.28
Version 2.3.29
Version 2.3.30
Version 2.3.31
Version 2.3.32
Version 2.3.33
Version 2.3.34
Version 2.3.35
Version 2.3.36
Version 2.3.37
Version 2.3.38
Version 2.3.39
Version 2.3.40
Version 2.3.41
Version 2.3.42
Version 2.3.43
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.10
Version 2.4.11
Version 2.4.12
Version 2.4.13
Version 2.4.14
Version 2.4.15
Version 2.4.16
Version 2.4.17
Version 2.4.18
Version 2.4.19
Version 2.4.20
Version 2.4.21
Version 2.4.22
Version 2.4.23
Version 2.4.24
Version 2.4.25
Version 2.4.3
Version 2.4.6
Version 2.4.7
Version 2.4.8
Version 2.4.9

Related CWEs

References (20)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.