Lucene search

K
cveRedhatCVE-2007-5708
HistoryOct 30, 2007 - 7:46 p.m.

CVE-2007-5708

2007-10-3019:46:00
CWE-399
redhat
web.nvd.nist.gov
39
2
openldap
proxy-caching
server
memory allocation
vulnerability
nvd
cve-2007-5708

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6

Confidence

Low

EPSS

0.037

Percentile

92.0%

slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors that prevent the array from being null terminated.

Affected configurations

Nvd
Node
openldapopenldapMatch1.0
OR
openldapopenldapMatch1.0.1
OR
openldapopenldapMatch1.0.2
OR
openldapopenldapMatch1.0.3
OR
openldapopenldapMatch1.1
OR
openldapopenldapMatch1.1.0
OR
openldapopenldapMatch1.1.1
OR
openldapopenldapMatch1.1.2
OR
openldapopenldapMatch1.1.3
OR
openldapopenldapMatch1.1.4
OR
openldapopenldapMatch1.2
OR
openldapopenldapMatch1.2.0
OR
openldapopenldapMatch1.2.1
OR
openldapopenldapMatch1.2.2
OR
openldapopenldapMatch1.2.3
OR
openldapopenldapMatch1.2.4
OR
openldapopenldapMatch1.2.5
OR
openldapopenldapMatch1.2.6
OR
openldapopenldapMatch1.2.7
OR
openldapopenldapMatch1.2.8
OR
openldapopenldapMatch1.2.9
OR
openldapopenldapMatch1.2.10
OR
openldapopenldapMatch1.2.11
OR
openldapopenldapMatch1.2.12
OR
openldapopenldapMatch1.2.13
OR
openldapopenldapMatch2.0
OR
openldapopenldapMatch2.0.0
OR
openldapopenldapMatch2.0.1
OR
openldapopenldapMatch2.0.2
OR
openldapopenldapMatch2.0.3
OR
openldapopenldapMatch2.0.4
OR
openldapopenldapMatch2.0.5
OR
openldapopenldapMatch2.0.6
OR
openldapopenldapMatch2.0.7
OR
openldapopenldapMatch2.0.8
OR
openldapopenldapMatch2.0.9
OR
openldapopenldapMatch2.0.10
OR
openldapopenldapMatch2.0.11
OR
openldapopenldapMatch2.0.11_9
OR
openldapopenldapMatch2.0.11_11
OR
openldapopenldapMatch2.0.11_11s
OR
openldapopenldapMatch2.0.12
OR
openldapopenldapMatch2.0.13
OR
openldapopenldapMatch2.0.14
OR
openldapopenldapMatch2.0.15
OR
openldapopenldapMatch2.0.16
OR
openldapopenldapMatch2.0.17
OR
openldapopenldapMatch2.0.18
OR
openldapopenldapMatch2.0.19
OR
openldapopenldapMatch2.0.20
OR
openldapopenldapMatch2.0.21
OR
openldapopenldapMatch2.0.22
OR
openldapopenldapMatch2.0.23
OR
openldapopenldapMatch2.0.24
OR
openldapopenldapMatch2.0.25
OR
openldapopenldapMatch2.0.26
OR
openldapopenldapMatch2.0.27
OR
openldapopenldapMatch2.1.2
OR
openldapopenldapMatch2.1.3
OR
openldapopenldapMatch2.1.4
OR
openldapopenldapMatch2.1.5
OR
openldapopenldapMatch2.1.6
OR
openldapopenldapMatch2.1.7
OR
openldapopenldapMatch2.1.8
OR
openldapopenldapMatch2.1.9
OR
openldapopenldapMatch2.1.10
OR
openldapopenldapMatch2.1.11
OR
openldapopenldapMatch2.1.12
OR
openldapopenldapMatch2.1.13
OR
openldapopenldapMatch2.1.14
OR
openldapopenldapMatch2.1.15
OR
openldapopenldapMatch2.1.16
OR
openldapopenldapMatch2.1.17
OR
openldapopenldapMatch2.1.18
OR
openldapopenldapMatch2.1.19
OR
openldapopenldapMatch2.1.20
OR
openldapopenldapMatch2.1.21
OR
openldapopenldapMatch2.1.22
OR
openldapopenldapMatch2.1.23
OR
openldapopenldapMatch2.1.24
OR
openldapopenldapMatch2.1.25
OR
openldapopenldapMatch2.1.26
OR
openldapopenldapMatch2.1.27
OR
openldapopenldapMatch2.1.28
OR
openldapopenldapMatch2.1.29
OR
openldapopenldapMatch2.1.30
OR
openldapopenldapMatch2.1_.20
OR
openldapopenldapMatch2.2.0
OR
openldapopenldapMatch2.2.1
OR
openldapopenldapMatch2.2.4
OR
openldapopenldapMatch2.2.5
OR
openldapopenldapMatch2.2.6
OR
openldapopenldapMatch2.2.7
OR
openldapopenldapMatch2.2.8
OR
openldapopenldapMatch2.2.9
OR
openldapopenldapMatch2.2.10
OR
openldapopenldapMatch2.2.11
OR
openldapopenldapMatch2.2.12
OR
openldapopenldapMatch2.2.13
OR
openldapopenldapMatch2.2.14
OR
openldapopenldapMatch2.2.15
OR
openldapopenldapMatch2.2.16
OR
openldapopenldapMatch2.2.17
OR
openldapopenldapMatch2.2.18
OR
openldapopenldapMatch2.2.19
OR
openldapopenldapMatch2.2.20
OR
openldapopenldapMatch2.2.21
OR
openldapopenldapMatch2.2.22
OR
openldapopenldapMatch2.2.23
OR
openldapopenldapMatch2.2.24
OR
openldapopenldapMatch2.2.25
OR
openldapopenldapMatch2.2.26
OR
openldapopenldapMatch2.2.27
OR
openldapopenldapMatch2.2.28_r2
OR
openldapopenldapMatch2.2.29_rev_1.134
OR
openldapopenldapMatch2.3.27_2.20061018
OR
openldapopenldapMatch2.3.28_2.20061022
OR
openldapopenldapMatch2.3.28_20061022
OR
openldapopenldapMatch2.3.28_e1.0.0
VendorProductVersionCPE
openldapopenldap1.0cpe:2.3:a:openldap:openldap:1.0:*:*:*:*:*:*:*
openldapopenldap1.0.1cpe:2.3:a:openldap:openldap:1.0.1:*:*:*:*:*:*:*
openldapopenldap1.0.2cpe:2.3:a:openldap:openldap:1.0.2:*:*:*:*:*:*:*
openldapopenldap1.0.3cpe:2.3:a:openldap:openldap:1.0.3:*:*:*:*:*:*:*
openldapopenldap1.1cpe:2.3:a:openldap:openldap:1.1:*:*:*:*:*:*:*
openldapopenldap1.1.0cpe:2.3:a:openldap:openldap:1.1.0:*:*:*:*:*:*:*
openldapopenldap1.1.1cpe:2.3:a:openldap:openldap:1.1.1:*:*:*:*:*:*:*
openldapopenldap1.1.2cpe:2.3:a:openldap:openldap:1.1.2:*:*:*:*:*:*:*
openldapopenldap1.1.3cpe:2.3:a:openldap:openldap:1.1.3:*:*:*:*:*:*:*
openldapopenldap1.1.4cpe:2.3:a:openldap:openldap:1.1.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 1191

Social References

More

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6

Confidence

Low

EPSS

0.037

Percentile

92.0%