SB2018081443 - NULL pointer dereference in ldb (Alpine package)
Published: August 14, 2018
Security Bulletin ID
SB2018081443
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2018-1140)
The vulnerability allows a remote attacker to cause denial of service attack.
The vulnerability exists due to improper input validation when processing data from the LDB database layer. A remote attacker can trigger NULL pointer dereference error and cause the LDAP server and DNS server to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=7f7614b183e9e8db99c0df510db7706b0b73f229
- https://git.alpinelinux.org/aports/commit/?id=702e0f24016274438056f4ad26d72f0dce4778c7
- https://git.alpinelinux.org/aports/commit/?id=0a2ff30aa228a3a3b837c73291e9c7b3e396b2f8
- https://git.alpinelinux.org/aports/commit/?id=8c6e5428a4982898bfe0a8d6e2c6c64d4f3f653f
- https://git.alpinelinux.org/aports/commit/?id=53e46bd2838462d43bb89139a98f91afc31b6a08
- https://git.alpinelinux.org/aports/commit/?id=92f3d2b28a5940acc5db51e3889b698e7146e812
- https://git.alpinelinux.org/aports/commit/?id=73b2c0f0439b1c5dafaa60daa3d4b63d614c21ea
- https://git.alpinelinux.org/aports/commit/?id=d773d4c9846c9af6fff4cf55c1942ce486760f82