← All CVEs

CVE-2015-1545

medium · 5

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

5
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2015-02-12
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
openldapopenldap2.4.13
openldapopenldap2.4.14
openldapopenldap2.4.15
openldapopenldap2.4.16
openldapopenldap2.4.17
openldapopenldap2.4.18
openldapopenldap2.4.19
openldapopenldap2.4.20
openldapopenldap2.4.21
openldapopenldap2.4.22
openldapopenldap2.4.23
openldapopenldap2.4.24
openldapopenldap2.4.25
openldapopenldap2.4.26
openldapopenldap2.4.27
openldapopenldap2.4.28
openldapopenldap2.4.29
openldapopenldap2.4.30
openldapopenldap2.4.31
openldapopenldap2.4.32
openldapopenldap2.4.33
openldapopenldap2.4.34
openldapopenldap2.4.35
openldapopenldap2.4.36
openldapopenldap2.4.37
openldapopenldap2.4.38
openldapopenldap2.4.39
openldapopenldap2.4.40

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-1545