Back

MEDIUM

openldap: modrdn processing IA5StringNormalize NULL pointer dereference

Published Jul 27, 2010

Description

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.

Affected products

Remediation

No remediation recorded yet.

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jul 27, 2010
Updated Aug 7, 2024
Reserved Jan 6, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 19, 2010