CVE-2010-4746Missing Release of Memory after Effective Lifetime in 389 Directory Server

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 17

Description

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-23jq-44mr-vjqc: Multiple memory leaks in the normalization functionality in 389 Directory Server before 12022-05-17
CVEList
CVE-2010-4746: Multiple memory leaks in the normalization functionality in 389 Directory Server before 12011-02-23

📋Vendor Advisories

1
Red Hat
Server: Multiple memory leaks in the normalization functionality2010-12-16

💬Community

1
Bugzilla
CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality2011-02-24
CVE-2010-4746 — 389 Directory Server vulnerability | cvebase