bind-dyndb-ldap DN Escaping Flaw Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1027341 |
|
SecurityTracker URL: http://securitytracker.com/id/1027341
|
|
CVE Reference:
CVE-2012-3429
(Links to External Site)
|
Date: Aug 3 2012
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in bind-dyndb-ldap. A remote user can cause denial of service conditions.
The software does not properly escape distinguished names (DNs) for LDAP queries. A remote user can send a specially crafted request to cause the target named service to crash.
|
Impact:
A remote user can cause the target named service to crash.
|
Solution:
The vendor has issued a source code fix, available at:
http://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit/?id=f345805c73c294db42452ae966c48fbc36c48006
|
Vendor URL: fedorahosted.org/bind-dyndb-ldap/ (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS:
Linux (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 03 Aug 2012 03:24:50 +0000
Subject: bind-dyndb-ldap
|
http://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit/?id=f345805c73c294db42452ae966c48fbc36c48006
CVE-2012-3429
|
|