CVE-2001-1314
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.28% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- critical path/injoin directory server · critical path/livecontent directory
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html
- http://ciac.llnl.gov/ciac/bulletins/l-116.shtmlPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2001-18.htmlThird Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
- http://www.kb.cert.org/vuls/id/657547US Government Resource
- http://www.kb.cert.org/vuls/id/JPLA-4ZKLEMUS Government Resource
- http://www.securityfocus.com/bid/3124Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html
- http://ciac.llnl.gov/ciac/bulletins/l-116.shtmlPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2001-18.htmlThird Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
- http://www.kb.cert.org/vuls/id/657547US Government Resource
- http://www.kb.cert.org/vuls/id/JPLA-4ZKLEMUS Government Resource
- http://www.securityfocus.com/bid/3124Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.