cbcvebase.
CVE-2010-0212
published 2010-07-28

CVE-2010-0212: OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly…

PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.22%
92.7th percentile
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianopenldap< openldap 2.4.23-1 (bookworm)openldap 2.4.23-1 (bookworm)
openldapopenldap
openldapopenldap>= 0 < 2.4.23-12.4.23-1
openldapopenldap>= 0 < 2.4.23-12.4.23-1
openldapopenldap>= 0 < 2.4.23-12.4.23-1
openldapopenldap>= 0 < 2.4.23-12.4.23-1
vmwareesxi
vmwarevmware_workstation

Detection & IOCsextracted from sources · hover to see the quote

processslapd
commandmodrdn (zero-length RDN destination string)
  • Monitor slapd for crashes triggered by modrdn requests containing a zero-length RDN destination string; a NULL pointer dereference in IA5StringNormalize (schema_init.c:2696) is the crash signature.
  • The vulnerability is pre-authentication on OpenLDAP 2.4.x; any unauthenticated remote LDAPv3 modrdn request with an empty RDN string should be treated as suspicious.
  • On OpenLDAP 2.3.x (RHEL-5), the attack requires an authenticated user with sufficient privileges to perform modrdn; selfwrite privilege alone is not sufficient.
  • Ubuntu deployments running slapd under the OpenLDAP AppArmor profile provide an additional containment layer; verify AppArmor confinement is active for slapd.
  • ·OpenLDAP versions 2.4.x prior to 2.4.23 are vulnerable pre-authentication; versions 2.3.x require authenticated modrdn privileges; versions 2.2.x and older (RHEL-4/RHEL-3) are not affected because IA5StringValidate rejects empty strings before IA5StringNormalize is reached.
  • ·The fix was introduced in OpenLDAP 2.4.23; the upstream patch adds an additional restriction disallowing empty values in DNs regardless of attribute syntax, rather than changing IA5StringValidate.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu9.8CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.