VDB

CVE-2002-1378

CVE-2002-1378 PUBLISHED CVSS 7.5 HIGH

Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests.

EPSS 7.00% · 93.7th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
7.00%
93.7th percentile

Affected Products

VendorProductVersions
openldapopenldap0
n/an/an/a

Timeline

  • Dec 17, 2002 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Apr 30, 2022 CVE Updated
  • May 21, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›