CVE-2015-1546
published 2015-02-12CVE-2015-1546: Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.41%
87.5th percentile
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| debian | openldap | < openldap 2.4.40-4 (bookworm) | openldap 2.4.40-4 (bookworm) |
| openldap | openldap | — | — |
| openldap | openldap | >= 0 < 2.4.40-4 | 2.4.40-4 |
| openldap | openldap | >= 0 < 2.4.40-4 | 2.4.40-4 |
| openldap | openldap | >= 0 < 2.4.40-4 | 2.4.40-4 |
| openldap | openldap | >= 0 < 2.4.40-4 | 2.4.40-4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openldap: slapd crash in valueReturnFilter cleanup
vendor_redhat·2015-02-03·CVSS 5.0
CVE-2015-1546 [MEDIUM] openldap: slapd crash in valueReturnFilter cleanup
openldap: slapd crash in valueReturnFilter cleanup
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
Statement: Although we do ship the vulnerable function, the attack vector demonstrated in the original report does not apply to us, as we've never backported the patch that introduces this particular attack vector. We're currently unaware of an attack vector that applies to us.
Red Hat Product Security has rated this issue as having a security impact of Moderate. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redh
Debian
CVE-2015-1546: openldap - Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c...
vendor_debian·2015·CVSS 5.0
CVE-2015-1546 [MEDIUM] CVE-2015-1546: openldap - Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c...
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
Scope: local
bookworm: resolved (fixed in 2.4.40-4)
bullseye: resolved (fixed in 2.4.40-4)
forky: resolved (fixed in 2.4.40-4)
sid: resolved (fixed in 2.4.40-4)
trixie: resolved (fixed in 2.4.40-4)
Apple
CVE-2015-1546: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 5.0
CVE-2015-1546 [MEDIUM] CVE-2015-1546: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2015-1546
Component: CVE-ID
GHSA
GHSA-cmjm-2wxx-774f: Double free vulnerability in the get_vrFilter function in servers/slapd/filter
ghsa_unreviewed·2022-05-14
CVE-2015-1546 [MEDIUM] GHSA-cmjm-2wxx-774f: Double free vulnerability in the get_vrFilter function in servers/slapd/filter
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
OSV
CVE-2015-1546: Double free vulnerability in the get_vrFilter function in servers/slapd/filter
osv·2015-02-12·CVSS 5.0
CVE-2015-1546 [MEDIUM] CVE-2015-1546: Double free vulnerability in the get_vrFilter function in servers/slapd/filter
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
No detection rules found.
Exploit-DB
Flash - PCRE Regex Compilation Zero-Length Assertion Arbitrary Bytecode Execution
exploitdb·2015-08-19
CVE-2015-3042 Flash - PCRE Regex Compilation Zero-Length Assertion Arbitrary Bytecode Execution
Flash - PCRE Regex Compilation Zero-Length Assertion Arbitrary Bytecode Execution
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=224&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id
There’s an error in the PCRE engine version used in Flash that allows the execution of arbitrary PCRE bytecode, with potential for memory corruption and RCE.
This issue is a duplicate of http://bugs.exim.org/show_bug.cgi?id=1546 originally reported to PCRE upstream by mikispag; I rediscovered the issue fuzzing Flash so have filed this bug report to track disclosure deadline for Adobe.
The issue occurs in the handling of zero-length assertions; ie assertions where the object of the assertion is prepended with the OP_BRAZERO operator.
Simplest testcase
Exploit-DB
Palo Alto Traps Server 3.1.2.1546 - Persistent Cross-Site Scripting
exploitdb·2015-03-31·CVSS 4.3
CVE-2015-2223 [MEDIUM] Palo Alto Traps Server 3.1.2.1546 - Persistent Cross-Site Scripting
Palo Alto Traps Server 3.1.2.1546 - Persistent Cross-Site Scripting
---
#!/usr/bin/ruby
=begin
Product: Palo Alto Traps Server (formerly Cyvera Endpoint Protection)
Vendor: Palo Alto Networks
Vulnerable Version(s): 3.1.2.1546
Tested Version: 3.1.2.1546
Advisory Publication: 29 March 2015
Vendor Notification: 17 October 2014
Vulnerability Type: Stored Cross Site Scripting
CVE Reference: CVE-2015-2223
Risk Level: High
Solution Status:
Discovered and Provided: Michael Hendrickx, help AG
About the product:
Palo Alto Traps is an advanced endpoint protection suite that detects attacks such as memory corruption, executable child processes, DLL hijacking, etc. Aside from optionally blocking it, it sends this “trap” to a central server for logging purposes.
About the vulnerability:
An attacker
Bugzilla
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
bugzilla·2016-01-25·CVSS 6.5
CVE-2015-8784 [MEDIUM] CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode()
A flaw was discovered in a way libtiff decodes special data. A potential out-of-bounds write could occur for specifically crafted images.
External bug report:
http://bugzilla.maptools.org/show_bug.cgi?id=2508
CVE assignment:
http://seclists.org/oss-sec/2016/q1/191
Upstream fix:
https://github.com/vadz/libtiff/commit/b18012dae552f85dcc5c57d3bf4e997a15b1cc1c
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1301653]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://r
Bugzilla
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8665 [MEDIUM] CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
An Out-of-bounds read flaw was found in libtiff. An attacker could create a specially-crafted TIFF file, which could cause libtiff to crash.
Reference:
http://www.openwall.com/lists/oss-security/2015/12/24/4
Discussion:
Please inform me when you will have a patch or at least a reference for the bugzilla.
Greetings
Petr
---
Patch for this and bug#1294427:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/
Bugzilla
CVE-2015-8668 libtiff: OOB read in bmp2tiff
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-8668 [CRITICAL] CVE-2015-8668 libtiff: OOB read in bmp2tiff
CVE-2015-8668 libtiff: OOB read in bmp2tiff
A heap-buffer oveflow was found in bmp2tiff, A tool used to created TIFF format files from BMP format image files. An attacker could provide a specially-crafted BMP format file, which when converted to TIFF format, using the bmp2tiff tool, could lead to bmp2tiff executable to crash.
Reference:
http://seclists.org/bugtraq/2015/Dec/138
Discussion:
I haven't completed my analysis yet, but for now I tend to say that this is only OOB read.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-
Bugzilla
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8683 [MEDIUM] CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files
An out-bounds-read flaw was found in the way libtiff processed CIE Lab image format files. A attacker could create a specially-crafted CIE Lab image format files which could cause libtiff to crash.
Reference:
http://seclists.org/oss-sec/2015/q4/583
Discussion:
Patch for this and bug#1294444:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
Bugzilla
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
bugzilla·2015-12-28·CVSS 9.8
CVE-2015-7554 [CRITICAL] CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extension tags
An Invalid memory write flaw was found in libtiff in the way it parsed certain extension tags when reading TIFF format files. An attacker could use this flaw to crash or even execute arbitrary code with the permission of the user running such an application compiled against libtiff.
Reference:
http://seclists.org/bugtraq/2015/Dec/137
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/errata/RHSA-2016-1546.html
---
*** Bug 1410063 has been marked as
Bugzilla
CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup
bugzilla·2015-02-09·CVSS 5.0
CVE-2015-1546 [MEDIUM] CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup
CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup
It was reported [1] that certain queries cause slapd to crash while freeing operation controls.
Upstream report: http://www.openldap.org/its/?findid=8046
Upstream patch: http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=2f1a2dd329b91afe561cd06b872d09630d4edb6a
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776991
Discussion:
Created openldap tracking bugs for this issue:
Affects: fedora-all [bug 1190646]
---
Statement:
Although we do ship the vulnerable function, the attack vector demonstrated in the original report does not apply to us, as we've never backported the patch that introduces this particular attack vector. We're currently unaware of an attack vector that applies to us.
Red Ha
Bugzilla
CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup [fedora-all]
bugzilla·2015-02-09·CVSS 5.0
CVE-2015-1546 [MEDIUM] CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup [fedora-all]
CVE-2015-1546 openldap: slapd crash in valueReturnFilter cleanup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00069.htmlhttp://secunia.com/advisories/62787http://www.mandriva.com/security/advisories?name=MDVSA-2015:073http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=2f1a2dd329b91afe561cd06b872d09630d4edb6ahttp://www.openldap.org/its/?findid=8046http://www.openwall.com/lists/oss-security/2015/02/07/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776991https://exchange.xforce.ibmcloud.com/vulnerabilities/100938https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00069.htmlhttp://secunia.com/advisories/62787http://www.mandriva.com/security/advisories?name=MDVSA-2015:073http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commit%3Bh=2f1a2dd329b91afe561cd06b872d09630d4edb6ahttp://www.openldap.org/its/?findid=8046http://www.openwall.com/lists/oss-security/2015/02/07/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776991https://exchange.xforce.ibmcloud.com/vulnerabilities/100938https://support.apple.com/HT204659
2015-02-12
Published