CVE-2017-9287

Severity
6.5MEDIUM
EPSS
39.0%
top 2.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateMay 13

Description

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

Debianopenldap< 2.4.44+dfsg-5+3
NVDopenldap/openldap2.4.44

Also affects: Debian Linux 8.0, Enterprise Linux 7.4, 7.5, 7.6, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rf87-xm6q-rwxc: servers/slapd/back-mdb/search2022-05-13
CVEList
CVE-2017-9287: servers/slapd/back-mdb/search2017-05-29
OSV
CVE-2017-9287: servers/slapd/back-mdb/search2017-05-29

📋Vendor Advisories

4
Ubuntu
OpenLDAP vulnerability2017-07-19
Ubuntu
OpenLDAP vulnerability2017-06-01
Red Hat
openldap: Double free vulnerability in servers/slapd/back-mdb/search.c2017-05-17
Debian
CVE-2017-9287: openldap - servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double ...2017

💬Community

2
Bugzilla
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c2017-05-30
Bugzilla
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c [fedora-all]2017-05-30
CVE-2017-9287 (MEDIUM CVSS 6.5) | servers/slapd/back-mdb/search.c in | cvebase.io