slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
2017-09-05T18:29:00.133
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 4.7 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:N/A:P
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openldap | openldap | ≤ 2.4.45 | Yes |
Application | oracle | blockchain_platform | < 21.1.2 | Yes |