5
CVSSv2

CVE-2006-5779

Published: 07/11/2006 Updated: 08/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenLDAP prior to 2.3.29 allows remote malicious users to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap

canonical ubuntu linux 6.10

canonical ubuntu linux 5.10

canonical ubuntu linux 6.06

Vendor Advisories

Evgeny Legerov discovered that the OpenLDAP libraries did not correctly truncate authcid names This situation would trigger an assert and abort the program using the libraries A remote attacker could send specially crafted bind requests that would lead to an LDAP server denial of service ...