CVE-2017-2668: Null Pointer Dereference
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Other sources
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2668?
CVE-2017-2668 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2017-2668?
To mitigate CVE-2017-2668, upgrade to 389-ds-base version 1.3.5.17 or 1.3.6.10 or later.
Who is affected by CVE-2017-2668?
CVE-2017-2668 affects users of 389-ds-base versions prior to 1.3.5.17 and 1.3.6.10.
What type of attack does CVE-2017-2668 exploit?
CVE-2017-2668 can be exploited through a specially crafted LDAP bind request.
What is the impact of CVE-2017-2668 on my system?
Exploitation of CVE-2017-2668 could result in the ns-slapd service crashing, leading to a denial of service.