4
CVSSv2

CVE-2007-6698

Published: 01/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The BDB backend for slapd in OpenLDAP prior to 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap

Vendor Advisories

Jonathan Clarke discovered that the OpenLDAP slapd server did not properly handle modify requests when using the Berkeley DB backend and specifying the NOOP control An authenticated user with modify permissions could send a crafted modify request and cause a denial of service via application crash Ubuntu 710 is not affected by this issue ( ...