First published: Fri Feb 11 2011(Updated: )
389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat 389 Directory Server | =1.2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0704 is classified as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2011-0704, you should upgrade the 389 Directory Server to a version that is not vulnerable to the empty modify request issue.
CVE-2011-0704 affects users of 389 Directory Server version 1.2.7.5 built with mozldap.
CVE-2011-0704 involves a denial of service attack that crashes the 389 Directory Server replica.
The exploit for CVE-2011-0704 works by sending an empty modify request to the 389 Directory Server, causing it to crash.