CVE-2010-4217: Use After Free
Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4217?
CVE-2010-4217 has a severity rating that indicates it can lead to denial of service, causing the daemon to crash.
How do I fix CVE-2010-4217?
To fix CVE-2010-4217, upgrade to IBM Tivoli Directory Server versions 6.0.0.8-TIV-ITDS-IF0007 or 6.1.0-TIV-ITDS-FP0005 or later.
What software versions are affected by CVE-2010-4217?
CVE-2010-4217 affects multiple versions of IBM Tivoli Directory Server, specifically versions prior to 6.0.0.8 and 6.1.0.
What kind of attack can exploit CVE-2010-4217?
CVE-2010-4217 can be exploited through a remote attack that sends an unbind request during a search operation.
Is there a workaround for CVE-2010-4217?
There is no documented workaround for CVE-2010-4217; upgrading to the patched versions is the recommended solution.