The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
2015-02-12T16:59:06.143
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openldap | openldap | 2.4.13 | Yes |
Application | openldap | openldap | 2.4.14 | Yes |
Application | openldap | openldap | 2.4.15 | Yes |
Application | openldap | openldap | 2.4.16 | Yes |
Application | openldap | openldap | 2.4.17 | Yes |
Application | openldap | openldap | 2.4.18 | Yes |
Application | openldap | openldap | 2.4.19 | Yes |
Application | openldap | openldap | 2.4.20 | Yes |
Application | openldap | openldap | 2.4.21 | Yes |
Application | openldap | openldap | 2.4.22 | Yes |
Application | openldap | openldap | 2.4.23 | Yes |
Application | openldap | openldap | 2.4.24 | Yes |
Application | openldap | openldap | 2.4.25 | Yes |
Application | openldap | openldap | 2.4.26 | Yes |
Application | openldap | openldap | 2.4.27 | Yes |
Application | openldap | openldap | 2.4.28 | Yes |
Application | openldap | openldap | 2.4.29 | Yes |
Application | openldap | openldap | 2.4.30 | Yes |
Application | openldap | openldap | 2.4.31 | Yes |
Application | openldap | openldap | 2.4.32 | Yes |
Application | openldap | openldap | 2.4.33 | Yes |
Application | openldap | openldap | 2.4.34 | Yes |
Application | openldap | openldap | 2.4.35 | Yes |
Application | openldap | openldap | 2.4.36 | Yes |
Application | openldap | openldap | 2.4.37 | Yes |
Application | openldap | openldap | 2.4.38 | Yes |
Application | openldap | openldap | 2.4.39 | Yes |
Application | openldap | openldap | 2.4.40 | Yes |