Short Name |
LDAP:INVALID:ENC_INVALID_LEN |
---|---|
Severity |
High |
Recommended |
No |
Category |
LDAP |
Release Date |
2004/01/29 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly is an LDAP message with a field contained in the BER encoding, whose length is not consistent with that specified for that field. This can also occur when the length of the inner field exceeds the length of an outer encapsulating field.
The Lightweight Directory Access Protocol (LDAP) is designed to be a lightweight access protocol for directory services supporting X.500 models. It offers a means of searching, fetching and manipulating directory content. Several input validation errors have been found to exist in OpenLDAP. The problems were discovered using the PROTOS project's LDAPv3 test suite. The problems enable remote attackers to cause an affected OpenLDAP server to crash, resulting in a denial of service condition. Further technical details are not available at this time.