5
CVE-2011-1067
- EPSS 1.42%
- Veröffentlicht 23.02.2011 19:00:02
- Zuletzt bearbeitet 16.06.2026 23:28:38
- Erkennungen
slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ 389 Directory Server Update alpha1 Version <= 1.2.8
Fedoraproject ≫ 389 Directory Server Version 1.2.1
Fedoraproject ≫ 389 Directory Server Version 1.2.2
Fedoraproject ≫ 389 Directory Server Version 1.2.3
Fedoraproject ≫ 389 Directory Server Version 1.2.5
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc4
Fedoraproject ≫ 389 Directory Server Version 1.2.6
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a4
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc6
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc7
Fedoraproject ≫ 389 Directory Server Version 1.2.6.1
Fedoraproject ≫ 389 Directory Server Version 1.2.7 Update alpha3
Fedoraproject ≫ 389 Directory Server Version 1.2.7.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.42% | 0.693 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://directory.fedoraproject.org/wiki/Release_Notes
http://secunia.com/advisories/43566
https://bugzilla.redhat.com/show_bug.cgi?id=668619
https://exchange.xforce.ibmcloud.com/vulnerabilities/65769