VDB
CVE-2002-1378
CVE-2002-1378
PUBLISHED
CVSS 7.5 HIGH
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests.
EPSS 7.00% · 93.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
7.00%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openldap | openldap | 0 |
| n/a | n/a | n/a |
Timeline
- Dec 17, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Apr 30, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- 6328 vdb
- N-043 third-party-advisory
- 200212-12 vendor-advisory
- MDKSA-2003:006 vendor-advisory
- CLA-2002:556 vendor-advisory
- openldap-multiple-bo(10800) vdb
- http://www.linuxsecurity.com/advisories/gentoo_advisory-2704.html url
- http://www.debian.org/security/2003/dsa-227 patch
- http://www.redhat.com/support/errata/RHSA-2003-040.html patch
- https://nvd.nist.gov/vuln/detail/CVE-2002-1378 advisory
- http://www.novell.com/linux/security/advisories/2002_047_openldap2.html url
- http://www.turbolinux.com/security/TLSA-2003-5.txt url