CVE-2017-9287

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

References

https://bugs.debian.org/863563

http://www.openldap.org/its/?findid=8655

http://www.securityfocus.com/bid/98736

http://www.securitytracker.com/id/1038591

http://www.debian.org/security/2017/dsa-3868

https://access.redhat.com/errata/RHSA-2017:1852

https://kc.mcafee.com/corporate/index?page=content&id=SB10365

Details

Source: MITRE

Published: 2017-05-29

Updated: 2021-07-31

Type: CWE-415

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 2.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* versions up to 2.4.44 (inclusive)

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
124018SUSE SLES12 Security Update : openldap2 (SUSE-SU-2019:0931-1)NessusSuSE Local Security Checks
high
121713Photon OS 1.0: Openldap PHSA-2017-0024NessusPhotonOS Local Security Checks
critical
111873Photon OS 1.0: Libxml2 / Ncurses / Openldap / Ruby PHSA-2017-0024 (deprecated)NessusPhotonOS Local Security Checks
critical
103060EulerOS 2.0 SP2 : openldap (EulerOS-SA-2017-1202)NessusHuawei Local Security Checks
medium
103059EulerOS 2.0 SP1 : openldap (EulerOS-SA-2017-1201)NessusHuawei Local Security Checks
medium
102735CentOS 7 : openldap (CESA-2017:1852)NessusCentOS Local Security Checks
medium
102649Scientific Linux Security Update : openldap on SL7.x x86_64 (20170801)NessusScientific Linux Local Security Checks
medium
102555openSUSE Security Update : openldap2 (openSUSE-2017-936)NessusSuSE Local Security Checks
medium
102282Oracle Linux 7 : openldap (ELSA-2017-1852)NessusOracle Linux Local Security Checks
medium
102144RHEL 7 : openldap (RHSA-2017:1852)NessusRed Hat Local Security Checks
medium
101795Fedora 25 : openldap (2017-1ca18683e4)NessusFedora Local Security Checks
medium
100803SUSE SLED12 / SLES12 Security Update : openldap2 (SUSE-SU-2017:1567-1)NessusSuSE Local Security Checks
medium
100591Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : openldap vulnerability (USN-3307-1)NessusUbuntu Local Security Checks
medium
100576Debian DLA-972-1 : openldap security updateNessusDebian Local Security Checks
medium
100522Debian DSA-3868-1 : openldap - security updateNessusDebian Local Security Checks
medium