First published: Thu Mar 20 2003(Updated: )
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenLDAP | <=2.1.12 | |
OpenLDAP | =2.0.2 | |
OpenLDAP | =2.0.11_11 | |
OpenLDAP | =2.1.15 | |
OpenLDAP | =2.1.10 | |
OpenLDAP | =2.0.22 | |
OpenLDAP | =2.0.9 | |
OpenLDAP | =2.0.15 | |
OpenLDAP | =2.1.14 | |
OpenLDAP | =2.0.14 | |
OpenLDAP | =2.0 | |
OpenLDAP | =2.0.1 | |
OpenLDAP | =2.0.13 | |
OpenLDAP | =2.0.20 | |
OpenLDAP | =2.0.10 | |
OpenLDAP | =2.0.16 | |
OpenLDAP | =2.0.23 | |
OpenLDAP | =2.0.25 | |
OpenLDAP | =2.0.11_11s | |
OpenLDAP | =2.0.27 | |
OpenLDAP | =2.0.3 | |
OpenLDAP | =2.1.11 | |
OpenLDAP | =2.0.7 | |
OpenLDAP | =2.0.11_9 | |
OpenLDAP | =2.0.12 | |
OpenLDAP | =2.0.19 | |
OpenLDAP | =2.0.4 | |
OpenLDAP | =2.1.12 | |
OpenLDAP | =2.0.21 | |
OpenLDAP | =2.0.11 | |
OpenLDAP | =2.0.8 | |
OpenLDAP | =2.1.16 | |
OpenLDAP | =2.1.4 | |
OpenLDAP | =2.0.17 | |
OpenLDAP | =2.0.18 | |
OpenLDAP | =2.0.6 | |
OpenLDAP | =2.0.5 | |
OpenLDAP | =2.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1201 has a severity level classified as a denial of service vulnerability.
To fix CVE-2003-1201, upgrade OpenLDAP to version 2.1.13 or later.
CVE-2003-1201 affects OpenLDAP versions 2.1.12 and earlier, as well as certain specific versions in the 2.0.x series.
CVE-2003-1201 involves a remote attack that leads to a segmentation fault and service disruption.
Yes, CVE-2003-1201 can be exploited by remote attackers without the need for authentication.