7.5
CVE-2014-8182
- EPSS 3.09%
- Veröffentlicht 02.01.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:18:43
- Erkennungen
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.09% | 0.86 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-193 Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
https://access.redhat.com/security/cve/cve-2014-8182
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-8182
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-8182
https://security-tracker.debian.org/tracker/CVE-2014-8182