CVE-2017-9287
published 2017-05-29CVE-2017-9287: servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
7.14%
93.6th percentile
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openldap | < openldap 2.4.44+dfsg-5 (bookworm) | openldap 2.4.44+dfsg-5 (bookworm) |
| mcafee | policy_auditor | < 6.5.1 | 6.5.1 |
| openldap | openldap | <= 2.4.44 | — |
| openldap | openldap | >= 0 < 2.4.44+dfsg-5 | 2.4.44+dfsg-5 |
| openldap | openldap | >= 0 < 2.4.44+dfsg-5 | 2.4.44+dfsg-5 |
| openldap | openldap | >= 0 < 2.4.44+dfsg-5 | 2.4.44+dfsg-5 |
| openldap | openldap | >= 0 < 2.4.44+dfsg-5 | 2.4.44+dfsg-5 |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenLDAP vulnerability
vendor_ubuntu·2017-07-19
CVE-2017-9287 OpenLDAP vulnerability
Title: OpenLDAP vulnerability
Summary: OpenLDAP could be made to crash if it received specially crafted
network traffic.
USN-3307-1 fixed a vulnerability in OpenLDAP. This update provides the
corresponding update for ubuntu 12.04 ESM.
Original advisory details:
Karsten Heymann discovered that OpenLDAP incorrectly handled certain search
requests. A remote attacker could use this issue to cause slapd to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenLDAP vulnerability
vendor_ubuntu·2017-06-01
CVE-2017-9287 OpenLDAP vulnerability
Title: OpenLDAP vulnerability
Summary: OpenLDAP could be made to crash if it received specially crafted network
traffic.
Karsten Heymann discovered that OpenLDAP incorrectly handled certain search
requests. A remote attacker could use this issue to cause slapd to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
vendor_redhat·2017-05-17·CVSS 6.5
CVE-2017-9287 [MEDIUM] CWE-416 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
A double-free flaw was found in the way OpenLDAP's slapd server using the MDB backend handled LDAP searches. A remote attacker with access to search the directory could potentially use this flaw to crash slapd by issuing a specially crafted LDAP search query.
Statement: This issue does not affect the versions of OpenLDAP as shipped with Red Hat Enterprise Linux 6 and 7 as they don't use the affected MDB backend in their default configurations. Red Hat Product Security has rated this
Debian
CVE-2017-9287: openldap - servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double ...
vendor_debian·2017·CVSS 6.5
CVE-2017-9287 [MEDIUM] CVE-2017-9287: openldap - servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double ...
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
Scope: local
bookworm: resolved (fixed in 2.4.44+dfsg-5)
bullseye: resolved (fixed in 2.4.44+dfsg-5)
forky: resolved (fixed in 2.4.44+dfsg-5)
sid: resolved (fixed in 2.4.44+dfsg-5)
trixie: resolved (fixed in 2.4.44+dfsg-5)
GHSA
GHSA-rf87-xm6q-rwxc: servers/slapd/back-mdb/search
ghsa_unreviewed·2022-05-13
CVE-2017-9287 [MEDIUM] CWE-415 GHSA-rf87-xm6q-rwxc: servers/slapd/back-mdb/search
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
OSV
CVE-2017-9287: servers/slapd/back-mdb/search
osv·2017-05-29·CVSS 6.5
CVE-2017-9287 [MEDIUM] CVE-2017-9287: servers/slapd/back-mdb/search
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
bugzilla·2017-05-30·CVSS 6.5
CVE-2017-9287 [MEDIUM] CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
Upstream patch:
https://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=0cee1ffb6021b1aae3fcc9581699da1c85a6dd6e
Discussion:
Created openldap tracking bugs for this issue:
Affects: fedora-all [bug 1456713]
---
External References:
http://www.openldap.org/its/?findid=8655
---
Statement:
This issue does not affect the versions of OpenLDAP as shipped with Red Hat Enterprise Linux 6 and 7 as they don't use the affected MDB backend in their default confi
Bugzilla
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c [fedora-all]
bugzilla·2017-05-30·CVSS 6.5
CVE-2017-9287 [MEDIUM] CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c [fedora-all]
CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
http://www.debian.org/security/2017/dsa-3868http://www.openldap.org/its/?findid=8655http://www.securityfocus.com/bid/98736http://www.securitytracker.com/id/1038591https://access.redhat.com/errata/RHSA-2017:1852https://bugs.debian.org/863563https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.debian.org/security/2017/dsa-3868http://www.openldap.org/its/?findid=8655http://www.securityfocus.com/bid/98736http://www.securitytracker.com/id/1038591https://access.redhat.com/errata/RHSA-2017:1852https://bugs.debian.org/863563https://kc.mcafee.com/corporate/index?page=content&id=SB10365https://www.oracle.com/security-alerts/cpuapr2022.html
2017-05-29
Published