CVE-2001-1306
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- sun/iplanet directory server
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20011102-01-IVendor Advisory
- http://www.cert.org/advisories/CA-2001-18.htmlPatch, Third Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
- http://www.kb.cert.org/vuls/id/276944Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/JPLA-4WESMMUS Government Resource
- ftp://patches.sgi.com/support/free/security/advisories/20011102-01-IVendor Advisory
- http://www.cert.org/advisories/CA-2001-18.htmlPatch, Third Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
- http://www.kb.cert.org/vuls/id/276944Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/JPLA-4WESMMUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.