CVE-2010-4746: Medium severity red hat 389 directory server vulnerability
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) SlapiAttr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4746?
CVE-2010-4746 has been classified as a denial of service vulnerability due to multiple memory leaks.
How do I fix CVE-2010-4746?
To mitigate CVE-2010-4746, upgrading to version 1.2.7.5 or later of 389 Directory Server is recommended.
Which versions of 389 Directory Server are affected by CVE-2010-4746?
CVE-2010-4746 affects 389 Directory Server versions up to and including 1.2.7.
What causes CVE-2010-4746?
CVE-2010-4746 is caused by memory leaks in the normalization functionality of 389 Directory Server.
Can CVE-2010-4746 be exploited remotely?
Yes, CVE-2010-4746 can be exploited remotely by attackers using badly behaved applications.