CVE-2014-8182
published 2020-01-02CVE-2014-8182: An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.09%
86.3th percentile
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openldap | — | — |
| openldap | openldap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openldap: crash in ldap_domain2hostlist when processing SRV records
vendor_redhat·2014-07-21·CVSS 7.5
CVE-2014-8182 [HIGH] openldap: crash in ldap_domain2hostlist when processing SRV records
openldap: crash in ldap_domain2hostlist when processing SRV records
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
An off-by-one error leading to a crash was discovered in openldap's processing of DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
Package: openldap (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2014-8182: openldap - An off-by-one error leading to a crash was discovered in openldap 2.4 when proce...
vendor_debian·2014·CVSS 7.5
CVE-2014-8182 [HIGH] CVE-2014-8182: openldap - An off-by-one error leading to a crash was discovered in openldap 2.4 when proce...
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-mr56-3w7m-88hw: An off-by-one error leading to a crash was discovered in openldap 2
ghsa_unreviewed·2022-05-17
CVE-2014-8182 [MEDIUM] GHSA-mr56-3w7m-88hw: An off-by-one error leading to a crash was discovered in openldap 2
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2014-8182https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-8182https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-8182https://security-tracker.debian.org/tracker/CVE-2014-8182https://access.redhat.com/security/cve/cve-2014-8182https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-8182https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-8182https://security-tracker.debian.org/tracker/CVE-2014-8182
2020-01-02
Published