VulnerabilityModified
CVE-2006-5779
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
HIGH 7.5EPSS 75.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 75.89% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- openldap/openldap · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://gleg.net/downloads/VULNDISCO_META_FREE.tar.gzBroken Link, Exploit
- http://gleg.net/vulndisco_meta.shtmlBroken Link, Exploit
- http://secunia.com/advisories/22750Broken Link, Vendor Advisory
- http://secunia.com/advisories/22953Broken Link, Vendor Advisory
- http://secunia.com/advisories/22996Broken Link, Vendor Advisory
- http://secunia.com/advisories/23125Broken Link, Vendor Advisory
- http://secunia.com/advisories/23133Broken Link, Vendor Advisory
- http://secunia.com/advisories/23152Broken Link, Vendor Advisory
- http://secunia.com/advisories/23170Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200611-25.xmlThird Party Advisory
- http://securityreason.com/securityalert/1831Broken Link
- http://securitytracker.com/id?1017166Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:208Broken Link
- http://www.novell.com/linux/security/advisories/2006_72_openldap2.htmlBroken Link
- http://www.openldap.org/its/index.cgi/Software%20Bugs?id=4740Exploit, Issue Tracking
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.033-openldap.htmlBroken Link
- http://www.securityfocus.com/archive/1/450728/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/20939Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2006/0066/Broken Link
- http://www.ubuntu.com/usn/usn-384-1Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4379Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30076Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-820Broken Link
- http://gleg.net/downloads/VULNDISCO_META_FREE.tar.gzBroken Link, Exploit
- http://gleg.net/vulndisco_meta.shtmlBroken Link, Exploit
- http://secunia.com/advisories/22750Broken Link, Vendor Advisory
- http://secunia.com/advisories/22953Broken Link, Vendor Advisory
- http://secunia.com/advisories/22996Broken Link, Vendor Advisory
- http://secunia.com/advisories/23125Broken Link, Vendor Advisory
- http://secunia.com/advisories/23133Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.