4
CVSSv2

CVE-2011-4079

Published: 27/10/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and previous versions allows remote malicious users to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap 2.0.2

openldap openldap 2.0.11_11

openldap openldap 2.1.15

openldap openldap 2.1.10

openldap openldap 2.3.5

openldap openldap 2.2.4

openldap openldap 2.2.22

openldap openldap 2.3.31

openldap openldap 2.3.42

openldap openldap 2.1.29

openldap openldap 2.2.18

openldap openldap 2.1.9

openldap openldap 1.2.6

openldap openldap 1.1.2

openldap openldap 2.0.22

openldap openldap 2.4.17

openldap openldap 2.4.6

openldap openldap 2.0.9

openldap openldap 2.2.0

openldap openldap 2.3.32

openldap openldap 2.1.19

openldap openldap 1.0

openldap openldap 1.2.7

openldap openldap 2.2.12

openldap openldap 2.2.20

openldap openldap 2.4.11

openldap openldap 2.0.15

openldap openldap 2.2.13

openldap openldap 2.1.30

openldap openldap 2.0.26

openldap openldap 2.1.5

openldap openldap 2.1.14

openldap openldap 2.1.21

openldap openldap 1.0.2

openldap openldap 2.3.41

openldap openldap 2.4.8

openldap openldap 2.1.24

openldap openldap 2.3.17

openldap openldap 2.1.20

openldap openldap 2.0.14

openldap openldap 2.0.7

openldap openldap 1.2.11

openldap openldap 1.1.0

openldap openldap 2.0.13

openldap openldap 2.0.27

openldap openldap 2.0.11_9

openldap openldap 2.3.12

openldap openldap 2.2.9

openldap openldap 2.1.26

openldap openldap 2.3.8

openldap openldap 2.2.27

openldap openldap 2.3.27

openldap openldap 2.3.36

openldap openldap 2.3.39

openldap openldap 2.3.43

openldap openldap 2.3.20

openldap openldap 2.1.17

openldap openldap 2.3.40

openldap openldap 2.3.13

openldap openldap 2.4.9

openldap openldap 2.1.2

openldap openldap 2.2.14

openldap openldap 2.1.6

openldap openldap 2.4.16

openldap openldap 2.0.3

openldap openldap 2.4.3

openldap openldap 2.3.38

openldap openldap 2.3.14

openldap openldap 2.2.10

openldap openldap 2.2.7

openldap openldap 1.2.12

openldap openldap 2.0.25

openldap openldap 2.1.12

openldap openldap 2.4.22

openldap openldap 2.0.12

openldap openldap 2.4.25

openldap openldap 2.1_.20

openldap openldap 2.2.24

openldap openldap 2.3.10

openldap openldap 2.3.26

openldap openldap 1.2.1

openldap openldap 1.1.4

openldap openldap 1.1

openldap openldap 1.2.10

openldap openldap 2.0.24

openldap openldap 1.1.1

openldap openldap 2.0.20

openldap openldap 1.2.2

openldap openldap 2.3.6

openldap openldap 2.3.30

openldap openldap 2.4.20

openldap openldap 1.0.1

openldap openldap 1.2.4

openldap openldap 2.0.4

openldap openldap 2.4.15

openldap openldap 2.0.16

openldap openldap 2.2.5

openldap openldap 2.3.18

openldap openldap 2.2.6

openldap openldap 2.1.25

openldap openldap 2.3.9

openldap openldap 2.3.7

openldap openldap 2.3.24

openldap openldap 2.4.18

openldap openldap 1.2.8

openldap openldap 2.1.27

openldap openldap

openldap openldap 2.3.21

openldap openldap 2.0.11_11s

openldap openldap 1.2.9

openldap openldap 2.0.19

openldap openldap 2.3.15

openldap openldap 2.2.21

openldap openldap 2.1.8

openldap openldap 2.2.1

openldap openldap 1.2.13

openldap openldap 2.4.7

openldap openldap 2.3.33

openldap openldap 2.0.10

openldap openldap 2.1.7

openldap openldap 2.0.1

openldap openldap 2.4.23

openldap openldap 2.4.24

openldap openldap 2.2.15

openldap openldap 2.0

openldap openldap 2.3.29

openldap openldap 2.0.23

openldap openldap 1.2.5

openldap openldap 2.2.11

openldap openldap 1.0.3

openldap openldap 2.2.17

openldap openldap 2.1.3

openldap openldap 2.3.25

openldap openldap 2.2.23

openldap openldap 2.3.19

openldap openldap 2.3.35

openldap openldap 2.1.11

openldap openldap 2.0.8

openldap openldap 2.1.13

openldap openldap 2.2.25

openldap openldap 2.1.23

openldap openldap 2.4.14

openldap openldap 2.4.19

openldap openldap 2.0.18

openldap openldap 1.2

openldap openldap 2.4.12

openldap openldap 2.1.16

openldap openldap 2.4.21

openldap openldap 2.1.28

openldap openldap 2.1.22

openldap openldap 2.3.28

openldap openldap 2.0.5

openldap openldap 2.3.11

openldap openldap 2.2.8

openldap openldap 2.3.37

openldap openldap 2.4.13

openldap openldap 2.3.23

openldap openldap 1.1.3

openldap openldap 2.0.11

openldap openldap 2.4.10

openldap openldap 2.2.26

openldap openldap 2.0.6

openldap openldap 2.3.16

openldap openldap 2.3.22

openldap openldap 2.0.17

openldap openldap 2.2.19

openldap openldap 2.3.34

openldap openldap 2.1.4

openldap openldap 1.2.3

openldap openldap 2.1.18

openldap openldap 2.2.16

openldap openldap 2.0.0

openldap openldap 2.0.21

openldap openldap 2.3.4

openldap openldap 1.2.0

Vendor Advisories

Debian Bug report logs - #647610 CVE-2011-4079: Denial of Service through off-by-one Package: openldap; Maintainer for openldap is Debian OpenLDAP Maintainers <pkg-openldap-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 4 Nov 2011 14:39:02 UTC Severity: grave T ...
An OpenLDAP server could potentially be made to crash if it received specially crafted network traffic from an authenticated user ...