CVE-2001-0977: Medium severity openldap OpenLDAP vulnerability
Published Jul 16, 2001
·Updated
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
Affected Software
39 affected components
openldap OpenLDAP=2.0.2
openldap OpenLDAP=1.2.6
openldap OpenLDAP=1.1.2
openldap OpenLDAP=1.0
openldap OpenLDAP=1.2.7
openldap OpenLDAP=1.0.2
openldap OpenLDAP=2.0.7
openldap OpenLDAP=1.2.11
openldap OpenLDAP=2.0.3
openldap OpenLDAP=1.2.12
openldap OpenLDAP=1.2.1
openldap OpenLDAP=1.1.4
openldap OpenLDAP=1.1
openldap OpenLDAP=1.2.10
openldap OpenLDAP=1.1.1
openldap OpenLDAP=1.2.2
openldap OpenLDAP=1.0.1
openldap OpenLDAP=1.2.4
openldap OpenLDAP=2.0.4
openldap OpenLDAP=1.2.8
Mandrakesoft Mandrake Single Network Firewall=7.2
openldap OpenLDAP=1.2.9
openldap OpenLDAP=2.0.1
openldap OpenLDAP=2.0
openldap OpenLDAP=1.2.5
openldap OpenLDAP=1.0.3
openldap OpenLDAP=1.2
openldap OpenLDAP=2.0.5
openldap OpenLDAP=1.1.3
openldap OpenLDAP=2.0.6
openldap OpenLDAP=1.2.3
Mandrakesoft Mandrake Linux=7.2
Debian Debian Linux=2.2
redhat Linux=7.0
redhat Linux=6.2
Mandrakesoft Mandrake Linux Corporate Server=1.0.1
Mandrakesoft Mandrake Linux=7.1
Mandrakesoft Mandrake Linux=8.0
redhat Linux=7.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 16, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0977?
CVE-2001-0977 has a severity level that can be classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2001-0977?
To fix CVE-2001-0977, it is recommended to upgrade to OpenLDAP version 2.0.8 or later.
3
What versions of OpenLDAP are affected by CVE-2001-0977?
CVE-2001-0977 affects OpenLDAP versions 1.x before 1.2.12 and 2.x before 2.0.8.
4
What kind of attack does CVE-2001-0977 exploit?
CVE-2001-0977 exploits the slapd component of OpenLDAP by sending an invalid Basic Encoding Rules (BER) length field.
5
Can CVE-2001-0977 lead to data loss?
While CVE-2001-0977 primarily causes denial of service, it does not specifically lead to data loss.