CVE-2011-0019
published 2011-02-23CVE-2011-0019: slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches…
PriorityP428high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.42%
69.9th percentile
slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | 389_directory_server | <= 1.2.7 | — |
| fedoraproject | 389_directory_server | <= 1.2.8 | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Server: crash with multiple simple paged result searches
vendor_redhat·2011-02-22·CVSS 7.5
CVE-2011-0019 [HIGH] Server: crash with multiple simple paged result searches
Server: crash with multiple simple paged result searches
slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.
Red Hat
Server: DoS via Simple Paged Results connections
vendor_redhat·2011-01-10·CVSS 7.5
CVE-2011-1067 [HIGH] Server: DoS via Simple Paged Results connections
Server: DoS via Simple Paged Results connections
slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.
Statement: Not vulnerable. This issue did not affect Red Hat Directory Server 8 packages.
Package: Directory Server (Red Hat Directory Server 8) - Affected
Red Hat
Server: Multiple memory leaks in the normalization functionality
vendor_redhat·2010-12-16·CVSS 5.0
CVE-2010-4746 [MEDIUM] CWE-401 Server: Multiple memory leaks in the normalization functionality
Server: Multiple memory leaks in the normalization functionality
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
Statement: Not vulnerable. This issue did not affect Red Hat Directory Server 8 packages.
Package: Directory Server (Red Hat Directory Server 8) - Affected
GHSA
GHSA-xc37-cv9h-f6mv: slapd (aka ns-slapd) in 389 Directory Server before 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-1067 [HIGH] CWE-20 GHSA-xc37-cv9h-f6mv: slapd (aka ns-slapd) in 389 Directory Server before 1
slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.
GHSA
GHSA-23jq-44mr-vjqc: Multiple memory leaks in the normalization functionality in 389 Directory Server before 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2010-4746 [HIGH] GHSA-23jq-44mr-vjqc: Multiple memory leaks in the normalization functionality in 389 Directory Server before 1
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
GHSA
GHSA-rxmx-rf7q-7wh5: slapd (aka ns-slapd) in 389 Directory Server 1
ghsa_unreviewed·2022-05-03
CVE-2011-0019 [HIGH] CWE-20 GHSA-rxmx-rf7q-7wh5: slapd (aka ns-slapd) in 389 Directory Server 1
slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
bugzilla·2011-02-24·CVSS 5.0
CVE-2010-4746 [MEDIUM] CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4746 to
the following vulnerability:
Multiple memory leaks in the normalization functionality in 389
Directory Server before 1.2.7.5 allow remote attackers to cause a
denial of service (memory consumption) via "badly behaved
applications," related to (1) Slapi_Attr mishandling in the DN
normalization code and (2) pointer mishandling in the syntax
normalization code, a different issue than CVE-2011-0019.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4746
[2] http://directory.fedoraproject.org/wiki/Release_Notes
[3] https://bugzilla.redhat.com/show_bug.cgi?id=663597
Discussion:
Nathan, Rich, did this affect
Bugzilla
CVE-2011-1067 Directory Server: DoS via Simple Paged Results connections
bugzilla·2011-02-24·CVSS 7.5
CVE-2011-1067 [HIGH] CVE-2011-1067 Directory Server: DoS via Simple Paged Results connections
CVE-2011-1067 Directory Server: DoS via Simple Paged Results connections
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1067 to
the following vulnerability:
slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not
properly manage the c_timelimit field of the connection table element,
which allows remote attackers to cause a denial of service (daemon
outage) via Simple Paged Results connections, as demonstrated by using
multiple processes to replay TCP sessions, a different vulnerability
than CVE-2011-0019.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1067
[2] http://directory.fedoraproject.org/wiki/Release_Notes
[3] https://bugzilla.redhat.com/show_bug.cgi?id=668619
Discussion:
Relevant git commit:
http://git.fedorahosted.or
Bugzilla
CVE-2011-0019 Directory Server: crash with multiple simple paged result searches
bugzilla·2011-01-19·CVSS 7.5
CVE-2011-0019 [HIGH] CVE-2011-0019 Directory Server: crash with multiple simple paged result searches
CVE-2011-0019 Directory Server: crash with multiple simple paged result searches
A flaw was found in the way that the Red Hat Directory Server handled simple paged result searches. If an unauthenticated user were able to send multiple simple paged search requests to Directory Server, it could cause the server to crash.
Discussion:
The 'upstream' bug is bug #666076.
---
Upstream bug report:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=666076
---
This issue has been addressed in following products:
Red Hat Directory Server 8 for RHEL 4
Red Hat Directory Server 8 for RHEL 5
Via RHSA-2011:0293 https://rhn.redhat.com/errata/RHSA-2011-0293.html
http://www.redhat.com/support/errata/RHSA-2011-0293.htmlhttp://www.securityfocus.com/bid/46489http://www.securitytracker.com/id?1025102https://bugzilla.redhat.com/show_bug.cgi?id=666076https://bugzilla.redhat.com/show_bug.cgi?id=670914http://www.redhat.com/support/errata/RHSA-2011-0293.htmlhttp://www.securityfocus.com/bid/46489http://www.securitytracker.com/id?1025102https://bugzilla.redhat.com/show_bug.cgi?id=666076https://bugzilla.redhat.com/show_bug.cgi?id=670914
2011-02-23
Published