CVE-2017-15134: Buffer Overflow
A flaw was found in 389-ds-base 1.3.6.1. Improper handling of a search filter in slapifiltersprintf in slapd/util.c can lead to remote server crash and denial of service.
Upstream patch:
https://pagure.io/389-ds-base/c/6aa2acdc3cad9
Other sources
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15134?
CVE-2017-15134 has been classified as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2017-15134?
To mitigate CVE-2017-15134, upgrade the 389-ds-base package to version 1.3.6.13 or later.
What can an attacker do with CVE-2017-15134?
An attacker could exploit CVE-2017-15134 to cause a denial of service by crashing the ns-slapd process.
What versions are affected by CVE-2017-15134?
CVE-2017-15134 affects 389-ds-base versions prior to 1.3.6.13, 1.3.7.9, and 1.4.0.5.
Is authentication required to exploit CVE-2017-15134?
No, CVE-2017-15134 can be exploited by remote, unauthenticated attackers.