CVE-2010-4789: Use After Free
Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4789?
CVE-2010-4789 has a severity rating that allows remote authenticated users to cause a denial of service, leading to a daemon crash.
How do I fix CVE-2010-4789?
To fix CVE-2010-4789, upgrade to the patched versions of IBM Tivoli Directory Server 6.0.0.65 or 6.3.0.1 or later.
Which versions of IBM Tivoli Directory Server are affected by CVE-2010-4789?
IBM Tivoli Directory Server versions 6.0 before 6.0.0.65 and 6.3 before 6.3.0.1 are affected by CVE-2010-4789.
Is CVE-2010-4789 an exploit that can be performed remotely?
Yes, CVE-2010-4789 can be exploited remotely by authenticated users.
What kind of impact does CVE-2010-4789 have on the system?
CVE-2010-4789 can lead to a denial of service condition by causing a crash of the affected daemon.