CVE-2017-17740

Severity
7.5HIGH
EPSS
6.2%
top 9.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 13

Description

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDopenldap/openldap2.4.45
NVDopensuse/leap15.0, 15.1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h7vm-9jwq-6c9r: contrib/slapd-modules/nops/nops2022-05-13
OSV
CVE-2017-17740: contrib/slapd-modules/nops/nops2017-12-18
CVEList
CVE-2017-17740: contrib/slapd-modules/nops/nops2017-12-18

📋Vendor Advisories

2
Red Hat
openldap: contrib/slapd-modules/nops/nops.c attempts to free stack buffer allowing remote attackers to cause a denial of service2017-10-20
Debian
CVE-2017-17740: openldap - contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops...2017

💬Community

2
Bugzilla
CVE-2017-17740 openldap: contrib/slapd-modules/nops/nops.c attempts to free stack buffer allowing remote attackers to cause a denial of service2017-12-18
Bugzilla
CVE-2017-17740 openldap: contrib/slapd-modules/nops/nops.c attempts to free stack buffer allowing remote attackers to cause a denial of service [fedora-all]2017-12-18
CVE-2017-17740 (HIGH CVSS 7.5) | contrib/slapd-modules/nops/nops.c i | cvebase.io