Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability

http://www.securityfocus.com/bid/52404

Security Info

Bugtraq ID: 52404
Class: Unknown
CVE: CVE-2012-1164
Remote: Yes
Local: No
Published: Feb 29 2012 12:00AM
Updated: Jul 11 2012 10:30AM
Credit: Mattias Andersson
Vulnerable: Red Hat Enterprise Linux Workstation Optional 6
Red Hat Enterprise Linux Workstation 6
Red Hat Enterprise Linux Server Optional 6
Red Hat Enterprise Linux Server 6
Red Hat Enterprise Linux HPC Node Optional 6
Red Hat Enterprise Linux HPC Node 6
Red Hat Enterprise Linux Desktop Optional 6
Red Hat Enterprise Linux Desktop 6
Oracle Enterprise Linux 6
OpenLDAP OpenLDAP 2.4.29
OpenLDAP OpenLDAP 2.4.23
OpenLDAP OpenLDAP 2.4.22
OpenLDAP OpenLDAP 2.4.3
OpenLDAP OpenLDAP 2.4.2
OpenLDAP OpenLDAP 2.4.1
OpenLDAP OpenLDAP 2.4
OpenLDAP OpenLDAP 2.3.41
OpenLDAP OpenLDAP 2.3.40
OpenLDAP OpenLDAP 2.3.39
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
OpenLDAP OpenLDAP 2.3.27
OpenLDAP OpenLDAP 2.3.25
OpenLDAP OpenLDAP 2.3.6
+ S.u.S.E. Linux Personal 9.1 x86_64
+ S.u.S.E. Linux Personal 9.1
+ S.u.S.E. Linux Personal 9.1
OpenLDAP OpenLDAP 2.4.24
OpenLDAP OpenLDAP 2.3.28-E1.0.0
OpenLDAP OpenLDAP 2.3.28-20061022
OpenLDAP OpenLDAP 2.3.28-2.20061022
OpenLDAP OpenLDAP 2.3.27-2.20061018
Avaya Aura Experience Portal 6.0
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Not Vulnerable: OpenLDAP OpenLDAP 2.4.30

Security Discussion

OpenLDAP is prone to a remote denial-of-service vulnerability.

Attackers can exploit this issue to deny service to legitimate users by crashing affected 'slapd' servers.

Proof of Concept and Security Exploits

Attackers use readily available network utilities to exploit this vulnerability.

Security Solution(s)

Solution:
Updates are available. Please see the references for more information.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated May 22, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services