CVE-2010-2222

Severity
7.5HIGH
EPSS
0.4%
top 37.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateApr 21

Description

The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r732-c3fc-99gm: The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer2022-04-21
CVEList
CVE-2010-2222: The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer2019-11-05

📋Vendor Advisories

1
Red Hat
redhat-ds/389: null deref in _ger_parse_control() for subjectdn can crash server2010-07-01

💬Community

1
Bugzilla
CVE-2010-2222 redhat-ds/389: null deref in _ger_parse_control() for subjectdn can crash server2010-06-16
CVE-2010-2222 (HIGH CVSS 7.5) | The _ger_parse_control function in | cvebase.io