cbcvebase.
CVE-2015-0283
published 2015-03-30

CVE-2015-0283: The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of…

PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.12%
86.5th percentile
The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianslapi-nis< slapi-nis 0.54.2-1 (bookworm)slapi-nis 0.54.2-1 (bookworm)
redhatslapi-nis<= 0.54.1
slapi-nis_projectslapi-nis>= 0 < 0.54.2-10.54.2-1
slapi-nis_projectslapi-nis>= 0 < 0.54.2-10.54.2-1
slapi-nis_projectslapi-nis>= 0 < 0.54.2-10.54.2-1

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.