4.3
CVSSv2

CVE-2012-2134

Published: 26/02/2014 Updated: 10/03/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap prior to 1.1.0rc1 does not properly handle LDAP query errors, which allows remote malicious users to cause a denial of service (infinite loop and named server hang) via a non-alphabet character in the base DN in an LDAP search DNS query.

Vulnerable Product Search on Vulmon Subscribe to Product

martin nagy bind-dyndb-ldap 0.2.0

martin nagy bind-dyndb-ldap 0.1.0

martin nagy bind-dyndb-ldap 1.1.0

martin nagy bind-dyndb-ldap 1.0.0

martin nagy bind-dyndb-ldap

Vendor Advisories

Synopsis Important: bind-dyndb-ldap security update Type/Severity Security Advisory: Important Topic An updated bind-dyndb-ldap package that fixes one security issue is nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact A ...