CVE-2006-0451Missing Release of Memory after Effective Lifetime in Redhat Fedora Core

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.8%
top 26.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 1

Description

Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-gp23-6585-vcq6: Multiple memory leaks in the LDAP component in Fedora Directory Server 12022-05-01
CVEList
CVE-2006-0451: Multiple memory leaks in the LDAP component in Fedora Directory Server 12006-02-14

📋Vendor Advisories

1
Red Hat
memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)2007-02-13
CVE-2006-0451 — Redhat Fedora Core vulnerability | cvebase