CVE-2015-1545 PUBLISHED

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

EPSS 64.84% · 98.4th percentile

Risk Scores

EPSS Score
64.84%
98.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSopenldap0, 2.4.31-1+nmu2ubuntu3, 2.4.31-1+nmu2ubuntu4

Timeline

References

Open in Interactive Console →