Red Hat 389 Directory Server ns-slapd ldapsearch Buffer Overflow

Strike ID:
E18-yu3u1
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
3
Year:
2018

Description

A stack buffer overflow vulnerability has been found in Red Hat 389 Directory Server. The vulnerability is due to improper handling of 'ldapsearch' query parameters. An attacker can exploit this vulnerability by issuing a special 'ldapsearch' query, allowing arbitrary code execution in the context of the user running the 'ns-slapd' daemon. An unsuccessful attack will cause the daemon to crash.

CVE

References

Bid