Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1321
    posted: 12/02/08
  • NSM Daily Update #1321
    posted: 12/02/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1321
    posted: 12/02/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1300
    posted: 12/02/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 12/01/08

Title: Red Hat Directory Server LDAP Memory Leak Multiple Remote Denial Of Service Vulnerabilities

Severity: MODERATE

Description:

Red Hat Directory Server is an LDAPv3-compliant authentication solution.

Directory Server is prone to multiple remote denial-of-service vulnerabilities due to memory leaks. An attacker may exploit these issues during the authentication / bind phases of an LDAP session or by making LDAP search requests. These issues include LDAP search requests made anonymously.

Successful attacks may allow the attacker to crash the application, denying access to legitimate users.

Directory Server 7.1, 8 EL4, and 8 EL5 are vulnerable.

Affected Products:

  • RedHat Directory Server 7.1
  • RedHat Directory Server 7.1 SP1
  • RedHat Directory Server 7.1 SP2
  • RedHat Directory Server 7.1 SP3
  • RedHat Directory Server 7.1 SP4
  • RedHat Directory Server 7.1 SP5
  • RedHat Directory Server 7.1 SP6
  • RedHat Directory Server 8 EL 4
  • RedHat Directory Server 8 EL 5

References: