CVE-2006-0451
published 2006-02-14CVE-2006-0451: Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.59%
72.9th percentile
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fedora_core | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp23-6585-vcq6: Multiple memory leaks in the LDAP component in Fedora Directory Server 1
ghsa_unreviewed·2022-05-01
CVE-2006-0451 [MEDIUM] GHSA-gp23-6585-vcq6: Multiple memory leaks in the LDAP component in Fedora Directory Server 1
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
Red Hat
memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
vendor_redhat·2007-02-13·CVSS 5.0
CVE-2006-0451 [MEDIUM] memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135http://secunia.com/advisories/18960http://www.securityfocus.com/bid/16677https://exchange.xforce.ibmcloud.com/vulnerabilities/24794http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135http://secunia.com/advisories/18960http://www.securityfocus.com/bid/16677https://exchange.xforce.ibmcloud.com/vulnerabilities/24794
2006-02-14
Published