Short Name |
LDAP:INVALID:MODRDN-NULL-RDN |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
LDAP |
Keywords |
OpenLDAP Modrdn RDN NULL String Denial of Service |
Release Date |
2010/10/25 |
Update Number |
1798 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in OpenLDAP. It is due to invalid memory access when handling a NULL string in a modrdn request. A remote attacker can exploit this by sending a malicious request through a modrdn request to connect to the target server. Successful exploitation allows cause termination of slapd daemon resulting in a denial-of-service condition.
OpenLDAP is prone to multiple vulnerabilities. Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application or cause denial-of-service conditions. OpenLDAP 2.4.22 is vulnerable; other versions may also be affected.