Out-of-bounds read in ldb - CVE-2019-3824
Published: February 27, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain perform denial of service attack or gain access to sensitive information.
The vulnerability exists due to a boundary condition within the ldb_wildcard_compare() function in ldb_match.c. A remote attacker can send a specially crafted LDAP request to the affected application, trigger out-of-bounds read error and perform denial of service attack or read portions of memory on the system.
Affected software
ldb (Debian package)
ldb (Ubuntu package)
How to mitigate CVE-2019-3824
ldb (Debian package) - update to 2:1.1.27-1+deb9u1
ldb (Ubuntu package) - addressed in versions 1:1.1.24-0ubuntu0.14.04.2, 2:1.1.24-1ubuntu3.1, 2:1.2.3-1ubuntu0.1, 2:1.4.0+really1.3.5-2ubuntu0.1