MEDIUM
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname
Published Jun 1, 2006
5.0
MEDIUMCVSS 2.0
EPSS 4.49%
Description
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.
Affected products
No data.
OR
- 2.2.1
- 2.2.11
- 2.2.12
- 2.2.13
- 2.2.14
- 2.2.15
- 2.2.16
- 2.2.17
- 2.2.18
- 2.2.19
- 2.2.20
- 2.2.21
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is not exploitable as the status file is only written to and read by the slurpd process. Therefore this is not a vulnerability that affects Red Hat Enterprise Linux 2.1, 3, or 4.
Weaknesses (0)
No CWE recorded.
References (17)
- http://secunia.com/advisories/20126 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/20495 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20685 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20848 third-party-advisoryx_refsource_SECUNIA
- http://www.gentoo.org/security/en/glsa/glsa-200606-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:096 vendor-advisoryx_refsource_MANDRIVA
- http://www.openldap.org/devel/cvsweb.cgi/servers/slurpd/st.c.diff?r1=1.21&r2=1.22&hideattic=1&sortbydate=0&f=h x_refsource_CONFIRMPatch
- http://www.openldap.org/devel/cvsweb.cgi/servers/slurpd/st.c?hideattic=1&sortbydate=0#rev1.22 x_refsource_CONFIRMPatch
- http://www.openldap.org/software/release/changes.html x_refsource_CONFIRMPatch
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.008-openldap.html vendor-advisoryx_refsource_OPENPKGPatch
- http://www.osvdb.org/25659 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/436674/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vupen.com/english/advisories/2006/1921 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-2754 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-2754
- https://usn.ubuntu.com/305-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-2754
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 1, 2006
Updated Aug 7, 2024
Reserved Jun 1, 2006
Link CVE-2006-2754
CISA Vulnrichment
Updated n/a