CVE-2006-0453
published 2006-02-14CVE-2006-0453: The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in…
PriorityP422high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.84%
76.6th percentile
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fedora_core | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
vendor_redhat·2007-02-13·CVSS 5.0
CVE-2006-0451 [MEDIUM] memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
Red Hat
security flaw
vendor_redhat·2005-02-14·CVSS 7.8
CVE-2006-0453 [HIGH] security flaw
security flaw
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.
GHSA
GHSA-22q9-7cmf-jjxp: The LDAP component in Fedora Directory Server 1
ghsa_unreviewed·2022-05-01
CVE-2006-0453 [HIGH] GHSA-22q9-7cmf-jjxp: The LDAP component in Fedora Directory Server 1
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.
No detection rules found.
No public exploits indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135http://secunia.com/advisories/18960http://www.securityfocus.com/bid/16677https://exchange.xforce.ibmcloud.com/vulnerabilities/24795http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135http://secunia.com/advisories/18960http://www.securityfocus.com/bid/16677https://exchange.xforce.ibmcloud.com/vulnerabilities/24795
2006-02-14
Published