CVE-2014-8182 PUBLISHED CVSS 7.5 HIGH

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

EPSS 5.15% · 89.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
5.15%
89.8th percentile

Affected Products

VendorProductVersions
debiandebian_linux8.0, 9.0, 10.0
openldapopenldap2.4, 2.4

Timeline

References

Open in Interactive Console →