The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2014-02-05 10:55
Updated : 2016-12-07 19:03
NVD link : CVE-2013-4449
Mitre link : CVE-2013-4449
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
debian
- debian_linux
openldap
- openldap