Lucene search

K
nvd[email protected]NVD:CVE-2011-0019
HistoryFeb 23, 2011 - 7:00 p.m.

CVE-2011-0019

2011-02-2319:00:01
CWE-20
web.nvd.nist.gov
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0.012

Percentile

85.0%

slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.

Affected configurations

Nvd
Node
fedoraproject389_directory_serverMatch1.2.7.5
Node
redhatdirectory_serverMatch8.2
OR
redhatdirectory_serverMatch8.2.3
VendorProductVersionCPE
fedoraproject389_directory_server1.2.7.5cpe:2.3:a:fedoraproject:389_directory_server:1.2.7.5:*:*:*:*:*:*:*
redhatdirectory_server8.2cpe:2.3:a:redhat:directory_server:8.2:*:*:*:*:*:*:*
redhatdirectory_server8.2.3cpe:2.3:a:redhat:directory_server:8.2.3:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0.012

Percentile

85.0%