CVE-2010-2222: Null Pointer Dereference
A vulnerability in Red Hat Directory Server and the 389 Directory Server was discovered. The code that parses the GER request (gerparsecontrol()) can dereference a NULL pointer. An unauthenticated user able to communicate with the Directory Server could use a crafted search query that would cause the Directory Server to crash.
This issue has been assigned the name CVE-2010-2222.
Other sources
The gerparsecontrol function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2010-2222?
CVE-2010-2222 is a vulnerability in Red Hat Directory Server 8 and the 389 Directory Server that allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
How does CVE-2010-2222 affect Red Hat Directory Server?
CVE-2010-2222 affects Red Hat Directory Server 8.0.
How does CVE-2010-2222 affect 389 Directory Server?
CVE-2010-2222 affects 389 Directory Server.
What is the severity of CVE-2010-2222?
CVE-2010-2222 has a severity rating of high (7.5).
How can I fix CVE-2010-2222?
To fix CVE-2010-2222, it is recommended to apply the necessary patches provided by Red Hat or upgrade to a version that is not affected by this vulnerability.