Back

MEDIUM

memory leaks using ber_scanf when handling bad BER packets (CVE-2006-0453)

Published Feb 14, 2006

Description

Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 14, 2006
Updated Aug 7, 2024
Reserved Jan 27, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 13, 2007