5.1
CVSSv2

CVE-2006-6493

Published: 13/12/2006 Updated: 08/03/2011
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and previous versions, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote malicious users to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap 1.0.3

openldap openldap 1.1

openldap openldap 1.1.0

openldap openldap 1.2.1

openldap openldap 1.2.10

openldap openldap 1.2.5

openldap openldap 1.2.6

openldap openldap 2.0.11

openldap openldap 2.0.11_11

openldap openldap 2.0.16

openldap openldap 2.0.17

openldap openldap 2.0.23

openldap openldap 2.0.24

openldap openldap 2.0.7

openldap openldap 2.0.8

openldap openldap 2.1.15

openldap openldap 2.1.16

openldap openldap 2.1.22

openldap openldap 2.1.23

openldap openldap 2.1.30

openldap openldap 2.1.4

openldap openldap 2.2.0

openldap openldap 2.2.1

openldap openldap 2.2.16

openldap openldap 2.2.17

openldap openldap 2.2.18

openldap openldap 2.2.25

openldap openldap 2.2.26

openldap openldap 2.2.8

openldap openldap 2.2.9

openldap openldap 1.0.1

openldap openldap 1.0.2

openldap openldap 1.2

openldap openldap 1.2.0

openldap openldap 1.2.3

openldap openldap 1.2.4

openldap openldap 2.0.0

openldap openldap 2.0.1

openldap openldap 2.0.10

openldap openldap 2.0.14

openldap openldap 2.0.15

openldap openldap 2.0.21

openldap openldap 2.0.22

openldap openldap 2.0.5

openldap openldap 2.0.6

openldap openldap 2.1.13

openldap openldap 2.1.14

openldap openldap 2.1.20

openldap openldap 2.1.21

openldap openldap 2.1.29

openldap openldap 2.1.3

openldap openldap 2.1.9

openldap openldap 2.1_.20

openldap openldap 2.2.14

openldap openldap 2.2.15

openldap openldap 2.2.23

openldap openldap 2.2.24

openldap openldap 2.2.6

openldap openldap 2.2.7

openldap openldap

openldap openldap 1.0

openldap openldap 1.1.3

openldap openldap 1.1.4

openldap openldap 1.2.13

openldap openldap 1.2.2

openldap openldap 1.2.9

openldap openldap 2.0

openldap openldap 2.0.12

openldap openldap 2.0.13

openldap openldap 2.0.2

openldap openldap 2.0.20

openldap openldap 2.0.27

openldap openldap 2.0.3

openldap openldap 2.0.4

openldap openldap 2.1.11

openldap openldap 2.1.12

openldap openldap 2.1.19

openldap openldap 2.1.2

openldap openldap 2.1.27

openldap openldap 2.1.28

openldap openldap 2.1.7

openldap openldap 2.1.8

openldap openldap 2.2.12

openldap openldap 2.2.13

openldap openldap 2.2.21

openldap openldap 2.2.22

openldap openldap 2.2.4

openldap openldap 2.2.5

openldap openldap 2.3.28_2006-10-22

openldap openldap 2.3.28_e1.0.0

openldap openldap 1.1.1

openldap openldap 1.1.2

openldap openldap 1.2.11

openldap openldap 1.2.12

openldap openldap 1.2.7

openldap openldap 1.2.8

openldap openldap 2.0.11_11s

openldap openldap 2.0.11_9

openldap openldap 2.0.18

openldap openldap 2.0.19

openldap openldap 2.0.25

openldap openldap 2.0.26

openldap openldap 2.0.9

openldap openldap 2.1.10

openldap openldap 2.1.17

openldap openldap 2.1.18

openldap openldap 2.1.24

openldap openldap 2.1.25

openldap openldap 2.1.26

openldap openldap 2.1.5

openldap openldap 2.1.6

openldap openldap 2.2.10

openldap openldap 2.2.11

openldap openldap 2.2.19

openldap openldap 2.2.20

openldap openldap 2.2.27

openldap openldap 2.2.28_r2

openldap openldap 2.3.27_2_2006-10-18

openldap openldap 2.3.28_2_2006-10-22

Exploits

/* * openldap-kbind-p00fc - OpenLDAP kbind remote exploit * * Only works on servers compiled with * --enable-kbind enable LDAPv2+ Kerberos IV bind (deprecated) [no] * * by Solar Eclipse <solareclipse@phreedomorg> * * Shoutouts to LSD for their l33t asm code and to all 0dd people * * Private 0dd code * */ #include <arpa ...