Input validation error in OpenLDAP - CVE-2015-6908

 

Input validation error in OpenLDAP - CVE-2015-6908

Published: September 11, 2015 / Updated: August 3, 2020


Vulnerability identifier: #VU33285
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-6908
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.


Affected software

OpenLDAP
Amazon Linux AMI
SUSE Linux
Opensuse
openldap (Alpine package)

How to mitigate CVE-2015-6908

Install update from vendor's website.

OpenLDAP - update to 2.4.43
openldap (Alpine package) - update to 2.4.35-r3

External References

Related Security Bulletins