CVE-2017-9287 PUBLISHED

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

EPSS 35.90% · 97.0th percentile

Risk Scores

EPSS Score
35.90%
97.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenldap0, 2.4.41+dfsg-1ubuntu2, 2.4.41+dfsg-1ubuntu3
Ubuntu:14.04:LTSopenldap2.4.31-1+nmu2ubuntu8.2, 0, 2.4.31-1+nmu2ubuntu8.3

Timeline

References

Open in Interactive Console →