Wind River Support Network

HomeDefectsLIN10-2817
Not to be fixed

LIN10-2817 : Security Advisory - openldap - CVE-2017-17740

Created: Dec 20, 2017    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

https://access.redhat.com/security/cve/cve-2017-17740

CVEs


Live chat
Online