The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openldap | Openldap | 2.4.13 (including) | 2.4.13 (including) |
Openldap | Openldap | 2.4.14 (including) | 2.4.14 (including) |
Openldap | Openldap | 2.4.15 (including) | 2.4.15 (including) |
Openldap | Openldap | 2.4.16 (including) | 2.4.16 (including) |
Openldap | Openldap | 2.4.17 (including) | 2.4.17 (including) |
Openldap | Openldap | 2.4.18 (including) | 2.4.18 (including) |
Openldap | Openldap | 2.4.19 (including) | 2.4.19 (including) |
Openldap | Openldap | 2.4.20 (including) | 2.4.20 (including) |
Openldap | Openldap | 2.4.21 (including) | 2.4.21 (including) |
Openldap | Openldap | 2.4.22 (including) | 2.4.22 (including) |
Openldap | Openldap | 2.4.23 (including) | 2.4.23 (including) |
Openldap | Openldap | 2.4.24 (including) | 2.4.24 (including) |
Openldap | Openldap | 2.4.25 (including) | 2.4.25 (including) |
Openldap | Openldap | 2.4.26 (including) | 2.4.26 (including) |
Openldap | Openldap | 2.4.27 (including) | 2.4.27 (including) |
Openldap | Openldap | 2.4.28 (including) | 2.4.28 (including) |
Openldap | Openldap | 2.4.29 (including) | 2.4.29 (including) |
Openldap | Openldap | 2.4.30 (including) | 2.4.30 (including) |
Openldap | Openldap | 2.4.31 (including) | 2.4.31 (including) |
Openldap | Openldap | 2.4.32 (including) | 2.4.32 (including) |
Openldap | Openldap | 2.4.33 (including) | 2.4.33 (including) |
Openldap | Openldap | 2.4.34 (including) | 2.4.34 (including) |
Openldap | Openldap | 2.4.35 (including) | 2.4.35 (including) |
Openldap | Openldap | 2.4.36 (including) | 2.4.36 (including) |
Openldap | Openldap | 2.4.37 (including) | 2.4.37 (including) |
Openldap | Openldap | 2.4.38 (including) | 2.4.38 (including) |
Openldap | Openldap | 2.4.39 (including) | 2.4.39 (including) |
Openldap | Openldap | 2.4.40 (including) | 2.4.40 (including) |
Openldap | Ubuntu | devel | * |
Openldap | Ubuntu | lucid | * |
Openldap | Ubuntu | precise | * |
Openldap | Ubuntu | trusty | * |
Openldap | Ubuntu | upstream | * |
Openldap | Ubuntu | utopic | * |
Openldap | Ubuntu | vivid | * |
Openldap | Ubuntu | vivid/stable-phone-overlay | * |
Openldap | Ubuntu | vivid/ubuntu-core | * |