Off-by-one in OpenLDAP and Debian Linux - CVE-2014-8182

 

Off-by-one in OpenLDAP and Debian Linux - CVE-2014-8182

Published: January 3, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34914
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8182
CWE-ID: CWE-193
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.


Affected software

OpenLDAP
Debian Linux

How to mitigate CVE-2014-8182

Install update from vendor's website.


External References

Related Security Bulletins