CVE-2011-1067: Input Validation
slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the ctimelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1067?
The severity of CVE-2011-1067 is classified as high due to its potential to cause a denial of service.
How do I fix CVE-2011-1067?
To fix CVE-2011-1067, upgrade to 389 Directory Server version 1.2.8 or later, which includes a patch for this vulnerability.
What impact does CVE-2011-1067 have on Red Hat 389 Directory Server?
CVE-2011-1067 allows attackers to exploit the connection table, leading to potential downtime or service disruption.
Is CVE-2011-1067 a remote vulnerability?
Yes, CVE-2011-1067 can be exploited remotely through Simple Paged Results connections.
Which versions of 389 Directory Server are affected by CVE-2011-1067?
CVE-2011-1067 affects all versions of 389 Directory Server before 1.2.8.