cbcvebase.
CVE-2017-9287
published 2017-05-29

CVE-2017-9287: servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenldap< openldap 2.4.44+dfsg-5 (bookworm)openldap 2.4.44+dfsg-5 (bookworm)
mcafeepolicy_auditor< 6.5.16.5.1
openldapopenldap<= 2.4.44
openldapopenldap>= 0 < 2.4.44+dfsg-52.4.44+dfsg-5
openldapopenldap>= 0 < 2.4.44+dfsg-52.4.44+dfsg-5
openldapopenldap>= 0 < 2.4.44+dfsg-52.4.44+dfsg-5
openldapopenldap>= 0 < 2.4.44+dfsg-52.4.44+dfsg-5
oracleblockchain_platform< 21.1.221.1.2
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM