7.5

CVE-2008-1677

Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Directory Server Version 7.1 Update sp1
Redhat ≫ Directory Server Version 7.1 Update sp2
Redhat ≫ Directory Server Version 7.1 Update sp3
Redhat ≫ Directory Server Version 7.1 Update sp4
Redhat ≫ Directory Server Version 7.1 Update sp5
Redhat ≫ Directory Server Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.93% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://secunia.com/advisories/30181
Broken Link
http://secunia.com/advisories/30185
Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0268.html
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0269.html
Third Party Advisory
http://www.securityfocus.com/bid/29126
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1020001
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=444712
Third Party Advisory
Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/42332
Third Party Advisory
VDB Entry