CVE-2012-1164
published 2012-06-29CVE-2012-1164: slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with…
PriorityP413low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
3.69%
88.5th percentile
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| debian | openldap | < openldap 2.4.31-1 (bookworm) | openldap 2.4.31-1 (bookworm) |
| openldap | openldap | <= 2.4.29 | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2012-1164: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 2.6
CVE-2012-1164 [LOW] CVE-2012-1164: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2012-1164
Component: CVE-2012-1164
Ubuntu
OpenLDAP vulnerabilities
vendor_ubuntu·2015-05-26·CVSS 2.6
CVE-2012-1164 [LOW] OpenLDAP vulnerabilities
Title: OpenLDAP vulnerabilities
Summary: OpenLDAP could be made to crash if it received specially crafted network
traffic.
It was discovered that OpenLDAP incorrectly handled certain search queries
that returned empty attributes. A remote attacker could use this issue to
cause OpenLDAP to assert, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-1164)
Michael Vishchers discovered that OpenLDAP improperly counted references
when the rwm overlay was used. A remote attacker could use this issue to
cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449)
It was discovered that OpenLDAP incorrectly handled certain empty attribute
lists in search requests. A remote attacker could use this issue to cause
OpenLDAP to crash, resulting in a
Red Hat
(slapd): Assertion failure by processing search queries requesting only attributes for particular entry
vendor_redhat·2012-01-29·CVSS 2.6
CVE-2012-1164 [LOW] (slapd): Assertion failure by processing search queries requesting only attributes for particular entry
(slapd): Assertion failure by processing search queries requesting only attributes for particular entry
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
Statement: This issue did not affect openldap as shipped with Red Hat Enterprise Linux 5 as it did not contain the relevant assertion. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2012-0899.html
Package: openldap (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-1164: openldap - slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of ser...
vendor_debian·2012·CVSS 2.6
CVE-2012-1164 [LOW] CVE-2012-1164: openldap - slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of ser...
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
Scope: local
bookworm: resolved (fixed in 2.4.31-1)
bullseye: resolved (fixed in 2.4.31-1)
forky: resolved (fixed in 2.4.31-1)
sid: resolved (fixed in 2.4.31-1)
trixie: resolved (fixed in 2.4.31-1)
GHSA
GHSA-cvmw-3c66-5wx9: slapd in OpenLDAP before 2
ghsa_unreviewed·2022-05-17
CVE-2012-1164 [LOW] CWE-119 GHSA-cvmw-3c66-5wx9: slapd in OpenLDAP before 2
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
OSV
openldap vulnerabilities
osv·2015-05-26·CVSS 2.6
CVE-2012-1164 [LOW] openldap vulnerabilities
openldap vulnerabilities
It was discovered that OpenLDAP incorrectly handled certain search queries
that returned empty attributes. A remote attacker could use this issue to
cause OpenLDAP to assert, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-1164)
Michael Vishchers discovered that OpenLDAP improperly counted references
when the rwm overlay was used. A remote attacker could use this issue to
cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449)
It was discovered that OpenLDAP incorrectly handled certain empty attribute
lists in search requests. A remote attacker could use this issue to cause
OpenLDAP to crash, resulting in a denial of service. (CVE-2015-1545)
OSV
CVE-2012-1164: slapd in OpenLDAP before 2
osv·2012-06-29·CVSS 2.6
CVE-2012-1164 [LOW] CVE-2012-1164: slapd in OpenLDAP before 2
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2668 CVE-2012-1164 openldap various flaws [fedora-all]
bugzilla·2012-06-06·CVSS 2.6
CVE-2012-2668 [LOW] CVE-2012-2668 CVE-2012-1164 openldap various flaws [fedora-all]
CVE-2012-2668 CVE-2012-1164 openldap various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=825875
Bugzilla
CVE-2012-1164 openldap (slapd): Assertion failure by processing search queries requesting only attributes for particular entry
bugzilla·2012-03-12·CVSS 2.6
CVE-2012-1164 [LOW] CVE-2012-1164 openldap (slapd): Assertion failure by processing search queries requesting only attributes for particular entry
CVE-2012-1164 openldap (slapd): Assertion failure by processing search queries requesting only attributes for particular entry
A denial of service flaw was found in the way the slapd server of the OpenLDAP, the Lightweight Directory Access Protocol applications and development suite, processed certain search queries requesting only attributes (no values) for a particular entry. A remote attacker could issue a specially-crafted LDAP search query, which once processed by a vulnerable slapd server would lead to assertion failure (slapd abort).
Upstream bug report:
[1] http://www.openldap.org/its/index.cgi/Software%20Bugs?id=7143
Original upstream patch:
[2] http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=ef2f5263de8802794e528cc2648ecfca369302ae
Further patches:
[3] http
http://rhn.redhat.com/errata/RHSA-2012-0899.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26http://secunia.com/advisories/48372http://secunia.com/advisories/49607http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:130http://www.openldap.org/its/index.cgi/Software%20Bugs?id=7143http://www.openldap.org/software/release/changes.htmlhttp://www.securityfocus.com/bid/52404https://seclists.org/bugtraq/2019/Dec/23https://support.apple.com/kb/HT210788http://rhn.redhat.com/errata/RHSA-2012-0899.htmlhttp://seclists.org/fulldisclosure/2019/Dec/26http://secunia.com/advisories/48372http://secunia.com/advisories/49607http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:130http://www.openldap.org/its/index.cgi/Software%20Bugs?id=7143http://www.openldap.org/software/release/changes.htmlhttp://www.securityfocus.com/bid/52404https://seclists.org/bugtraq/2019/Dec/23https://support.apple.com/kb/HT210788
2012-06-29
Published