Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11035
HistoryJan 15, 2019 - 8:56 a.m.

Denial Of Service (DoS)

2019-01-1508:56:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.94 High

EPSS

Percentile

99.2%

openldap is vulnerable to denial of service (DoS) attacks. The vulnerability exists as the rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.