First published: Mon Jul 16 2001(Updated: )
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Iplanet Directory Server | <=4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1306 is rated as a high severity vulnerability due to its ability to cause denial of service and potential remote code execution.
To fix CVE-2001-1306, upgrade to iPlanet Directory Server version 4.1.5 or later, which addresses this vulnerability.
CVE-2001-1306 affects iPlanet Directory Server version 4.1.4 and earlier.
CVE-2001-1306 involves a denial of service attack that can crash the server and potentially lead to arbitrary code execution.
Yes, CVE-2001-1306 can be exploited remotely by attackers sending malicious invalid BER length fields.