fkie_cve-2007-5708
Vulnerability from fkie_nvd
Published
2007-10-30 19:46
Modified
2025-04-09 00:30
Severity ?
Summary
slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors that prevent the array from being null terminated.
References
secalert@redhat.comhttp://secunia.com/advisories/27424Patch, Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/27683Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/27756Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/27868Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/29225Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/29461Vendor Advisory
secalert@redhat.comhttp://secunia.com/advisories/29682Vendor Advisory
secalert@redhat.comhttp://security.gentoo.org/glsa/glsa-200803-28.xml
secalert@redhat.comhttp://www.debian.org/security/2008/dsa-1541
secalert@redhat.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:058
secalert@redhat.comhttp://www.novell.com/linux/security/advisories/2007_24_sr.html
secalert@redhat.comhttp://www.openldap.org/its/index.cgi/Software%20Bugs?id=5163
secalert@redhat.comhttp://www.openldap.org/lists/openldap-announce/200710/msg00001.htmlPatch
secalert@redhat.comhttp://www.redhat.com/archives/fedora-package-announce/2007-November/msg00460.html
secalert@redhat.comhttp://www.securityfocus.com/bid/26245
secalert@redhat.comhttp://www.ubuntu.com/usn/usn-551-1
secalert@redhat.comhttp://www.vupen.com/english/advisories/2007/3645Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/27424Patch, Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/27683Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/27756Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/27868Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/29225Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/29461Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/29682Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://security.gentoo.org/glsa/glsa-200803-28.xml
af854a3a-2127-422b-91ae-364da2661108http://www.debian.org/security/2008/dsa-1541
af854a3a-2127-422b-91ae-364da2661108http://www.mandriva.com/security/advisories?name=MDVSA-2008:058
af854a3a-2127-422b-91ae-364da2661108http://www.novell.com/linux/security/advisories/2007_24_sr.html
af854a3a-2127-422b-91ae-364da2661108http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5163
af854a3a-2127-422b-91ae-364da2661108http://www.openldap.org/lists/openldap-announce/200710/msg00001.htmlPatch
af854a3a-2127-422b-91ae-364da2661108http://www.redhat.com/archives/fedora-package-announce/2007-November/msg00460.html
af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/26245
af854a3a-2127-422b-91ae-364da2661108http://www.ubuntu.com/usn/usn-551-1
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2007/3645Vendor Advisory
Impacted products
Vendor Product Version
openldap openldap 1.0
openldap openldap 1.0.1
openldap openldap 1.0.2
openldap openldap 1.0.3
openldap openldap 1.1
openldap openldap 1.1.0
openldap openldap 1.1.1
openldap openldap 1.1.2
openldap openldap 1.1.3
openldap openldap 1.1.4
openldap openldap 1.2
openldap openldap 1.2.0
openldap openldap 1.2.1
openldap openldap 1.2.2
openldap openldap 1.2.3
openldap openldap 1.2.4
openldap openldap 1.2.5
openldap openldap 1.2.6
openldap openldap 1.2.7
openldap openldap 1.2.8
openldap openldap 1.2.9
openldap openldap 1.2.10
openldap openldap 1.2.11
openldap openldap 1.2.12
openldap openldap 1.2.13
openldap openldap 2.0
openldap openldap 2.0.0
openldap openldap 2.0.1
openldap openldap 2.0.2
openldap openldap 2.0.3
openldap openldap 2.0.4
openldap openldap 2.0.5
openldap openldap 2.0.6
openldap openldap 2.0.7
openldap openldap 2.0.8
openldap openldap 2.0.9
openldap openldap 2.0.10
openldap openldap 2.0.11
openldap openldap 2.0.11_9
openldap openldap 2.0.11_11
openldap openldap 2.0.11_11s
openldap openldap 2.0.12
openldap openldap 2.0.13
openldap openldap 2.0.14
openldap openldap 2.0.15
openldap openldap 2.0.16
openldap openldap 2.0.17
openldap openldap 2.0.18
openldap openldap 2.0.19
openldap openldap 2.0.20
openldap openldap 2.0.21
openldap openldap 2.0.22
openldap openldap 2.0.23
openldap openldap 2.0.24
openldap openldap 2.0.25
openldap openldap 2.0.26
openldap openldap 2.0.27
openldap openldap 2.1.2
openldap openldap 2.1.3
openldap openldap 2.1.4
openldap openldap 2.1.5
openldap openldap 2.1.6
openldap openldap 2.1.7
openldap openldap 2.1.8
openldap openldap 2.1.9
openldap openldap 2.1.10
openldap openldap 2.1.11
openldap openldap 2.1.12
openldap openldap 2.1.13
openldap openldap 2.1.14
openldap openldap 2.1.15
openldap openldap 2.1.16
openldap openldap 2.1.17
openldap openldap 2.1.18
openldap openldap 2.1.19
openldap openldap 2.1.20
openldap openldap 2.1.21
openldap openldap 2.1.22
openldap openldap 2.1.23
openldap openldap 2.1.24
openldap openldap 2.1.25
openldap openldap 2.1.26
openldap openldap 2.1.27
openldap openldap 2.1.28
openldap openldap 2.1.29
openldap openldap 2.1.30
openldap openldap 2.1_.20
openldap openldap 2.2.0
openldap openldap 2.2.1
openldap openldap 2.2.4
openldap openldap 2.2.5
openldap openldap 2.2.6
openldap openldap 2.2.7
openldap openldap 2.2.8
openldap openldap 2.2.9
openldap openldap 2.2.10
openldap openldap 2.2.11
openldap openldap 2.2.12
openldap openldap 2.2.13
openldap openldap 2.2.14
openldap openldap 2.2.15
openldap openldap 2.2.16
openldap openldap 2.2.17
openldap openldap 2.2.18
openldap openldap 2.2.19
openldap openldap 2.2.20
openldap openldap 2.2.21
openldap openldap 2.2.22
openldap openldap 2.2.23
openldap openldap 2.2.24
openldap openldap 2.2.25
openldap openldap 2.2.26
openldap openldap 2.2.27
openldap openldap 2.2.28_r2
openldap openldap 2.2.29_rev_1.134
openldap openldap 2.3.27_2.20061018
openldap openldap 2.3.28_2.20061022
openldap openldap 2.3.28_20061022
openldap openldap 2.3.28_e1.0.0



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "086DC60F-F530-4515-8F3D-87F30DB9B322",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "1D538927-82D5-476E-9C85-2E9297316D44",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "2A904832-A6D6-45D4-B07C-79ED1FE47A80",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "1BB554A4-EEC2-4E17-9F32-27A580B9E389",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "191DB249-6A73-4561-8CCA-565D1525CB31",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "423F9D3A-6AA7-4D64-B872-2C867EEFC3DC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "34A5D9A5-FB1D-4ACF-846A-4DB73196122C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "41400CE6-FA51-435C-93F7-B31FE42F18AE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "6022ABEB-6825-4A5F-9884-74F94C2387F8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "D2F15789-334D-460D-B5B3-FCC71087D107",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F77B1548-BB6D-4618-AE7B-E97F91A0AF5D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "1CC52235-72DA-4EF4-870A-AF25181DB56C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "B7064C52-1211-42B8-BF1F-C22D800AED07",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "1CD95826-E44A-48C6-BAAB-77A905CAE6B3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "FEEA6BB6-41FC-4F15-A95F-9B052F062454",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "E90766C1-6DBD-435C-85E1-920DAFA26D67",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "8CD13DAE-9588-4540-9183-FB80C507F985",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "526366F3-52F0-4816-A356-8F39B718C048",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "AC07AD0D-5DF9-41A4-8592-CEFF1842355D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "30017C56-42A9-4AF9-B5B3-7357E424F837",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "C8A51F38-3F5A-4F6D-93EE-776B5C2FF48F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "8DBEC27E-3220-42CE-B6CC-675F387CB506",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "E641DFFB-CBAF-4DCF-944F-443CFF836A53",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "A552E270-5C9C-40DC-B23D-97C8D995B8FE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:1.2.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "53DF812C-E1F8-46D3-A072-3FBE696ADC33",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "552F2E25-DDB8-49A6-844A-8520696DBE5B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "149EBFB7-B58F-4557-8E46-6DF88BB5E57E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "03D75A36-41C4-464F-8DC4-42C841ABC087",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "1C3EE919-D05C-4625-85FE-132F6F2B932C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "20D99A58-8D7E-4586-A9BF-1DD2A1DBB8D3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "DEBA0118-545E-4D7B-B819-34D157B2BA6D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "67826609-F4CA-42CB-A5D0-B4503DDE2C92",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "61676BBD-95B8-44C9-BD66-79F00381BF86",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "719A9B1D-8E32-461F-BCD4-F72C6AD3E63E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "BFD73969-39F8-4849-AF6A-15ACDC2E4537",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "DB8C1DD2-865A-4CF2-8137-3C40C01C9EAC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "EE38B045-2224-43D1-8618-0885505865C6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "5D26DAC5-EDBD-42D8-A877-1E6EA666D72B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.11_9:*:*:*:*:*:*:*",
              "matchCriteriaId": "E7AE325E-514C-40A1-AA56-D605377B5D90",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.11_11:*:*:*:*:*:*:*",
              "matchCriteriaId": "19397A11-E549-4F31-8007-8D5F3C0AABB1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.11_11s:*:*:*:*:*:*:*",
              "matchCriteriaId": "1C659213-271D-4F22-AE14-A1646A612D2A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "67B0A2B6-C560-4AE0-BC79-3C7BC9163EE0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "566406CE-368A-4799-A112-E5DFC5B333D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "E5CCC734-C15B-4D2B-BF83-F214F807C44E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.15:*:*:*:*:*:*:*",
              "matchCriteriaId": "64796893-A90D-4B7D-BDBC-0087B57AF7E5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "39914C6A-F4DB-43CC-B2B6-097365E55D34",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "5BFDD8F7-AAFD-453F-99A4-F9C0424EA791",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BFEEAA6-0B50-4644-A183-F5FEE7BD7EEC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "920FC1DB-95E2-4367-BF20-77D75BD7617D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "28E643F8-005A-4170-8275-8E4AB5C25209",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.21:*:*:*:*:*:*:*",
              "matchCriteriaId": "C8A34C63-C17D-4026-B409-AA9A56529B87",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.22:*:*:*:*:*:*:*",
              "matchCriteriaId": "4EA863B0-A6AB-44BD-84E8-B6C885EFFE10",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.23:*:*:*:*:*:*:*",
              "matchCriteriaId": "24BFAEC7-6256-4B8F-83F5-60FBD1571936",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.24:*:*:*:*:*:*:*",
              "matchCriteriaId": "83227371-ACC3-4217-BFF9-0A3AAADD50DD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.25:*:*:*:*:*:*:*",
              "matchCriteriaId": "734B8101-BEAC-40AB-81EA-2516CA20BC93",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.26:*:*:*:*:*:*:*",
              "matchCriteriaId": "F0BD5253-FBC9-4384-8FC3-4E384582BE91",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.0.27:*:*:*:*:*:*:*",
              "matchCriteriaId": "AA73658A-8834-4EC2-8D8F-3A7D1C834669",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "06BCE98E-546C-4852-BAE2-CF525A778B48",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "94284C78-255E-43B7-A33E-FBC25BABEA2A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "4B298BAA-5584-4193-A3DB-31FBB0BD12B2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "90604A40-A1F5-4F23-9B8C-472E8C794B59",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "1418EC80-2F42-4C1B-BA38-CA5BDEF83F4B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "9BC65FE9-348D-4468-A1EF-2AC5C673DB07",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "B3A400A0-B9D7-4CB2-82EA-49A599C2B30B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "65587514-46AB-4D70-B7C2-FBED7F78D13D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "7951BAAB-CB06-4F19-891A-E07E2B3C8701",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "82EC30A1-4150-44DC-89F7-5A64B8CC4A84",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "9DF04D97-A561-427B-9891-A1423B86F164",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "1E74B0C8-2D64-4BF2-B152-87909E3029EB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "88F6CA0B-ED91-4085-8EE0-1F4256747621",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.15:*:*:*:*:*:*:*",
              "matchCriteriaId": "B90657E7-D651-4E1E-8035-13A1F024E3C2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "7BBE5477-BE27-412A-9BA9-9690F746B4F4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "31300FA3-C57D-4564-927E-B06C0229BE8B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "342E414D-8ED6-4E5A-88F0-57B5846A3EB8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "7C0BD0FD-BD80-4197-8479-BBB070DAB890",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "FC9CA4EF-61F1-407B-B2BF-B4AFD68F50BE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.21:*:*:*:*:*:*:*",
              "matchCriteriaId": "EB80C814-5B28-46CC-8237-70A558BF049C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.22:*:*:*:*:*:*:*",
              "matchCriteriaId": "832AC063-6004-4A78-A964-45906361F9C3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.23:*:*:*:*:*:*:*",
              "matchCriteriaId": "E7C40DFD-4FB8-40AA-ABA4-194DED1241A4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.24:*:*:*:*:*:*:*",
              "matchCriteriaId": "992733F2-000F-4E27-8D19-AF18543E57BB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.25:*:*:*:*:*:*:*",
              "matchCriteriaId": "B36E0E49-D908-4A19-A621-6E7FB3E59A18",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.26:*:*:*:*:*:*:*",
              "matchCriteriaId": "74779CA2-6741-4053-8C23-98A1F938B264",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.27:*:*:*:*:*:*:*",
              "matchCriteriaId": "930DAA18-113F-42B0-8382-8579575D238F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.28:*:*:*:*:*:*:*",
              "matchCriteriaId": "98F50353-EBFB-4DE5-8D35-80C672A12E41",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.29:*:*:*:*:*:*:*",
              "matchCriteriaId": "18A4F43F-8E4F-4203-B640-02BBB28052A4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1.30:*:*:*:*:*:*:*",
              "matchCriteriaId": "28063C54-EE5E-44EC-8D47-E880C2BB45BF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.1_.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "E8BCFC49-6505-4713-A06C-A64782A34414",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "BAE01BA8-416B-4419-99E5-81C1FA404FBC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "3C2F45B8-B9FB-4D43-B2DD-98413F5F2B85",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "0F611094-500A-4306-8C15-4878135FA45D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "32096DE5-3F2C-4FF7-BDC6-E316DFDC97A7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "FE197F27-CB34-4B0E-A30A-C9C87295AAD3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "10A4256F-EC89-425F-86FD-B0DE243EBF2C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A34127E-507D-4F72-9F93-B23F91DB0F53",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "B7A2D5D9-3E7E-4420-A338-B05A8C077229",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "C76EF100-3328-4C70-A123-50A4ECFF539E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "1DCE7803-E652-4A17-8EEB-B91C81CF48E5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "DA5CB439-5F0B-40CF-8564-6875CAC74FCD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "BB5E524E-1B71-46B5-A14E-C2342851C0FD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "FE103338-9AE7-4230-A8B2-09273004B4D1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.15:*:*:*:*:*:*:*",
              "matchCriteriaId": "12621DED-ABF1-47A7-961C-E6DE1F6302AA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "C8026929-4845-46E4-A6F8-E60CA498201B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "DE01BD68-D6DC-4220-A3F0-71961CEA205F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "68DE3F16-E171-4FA3-9B00-3F944A4E7604",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "63F7B718-0E5C-4900-A5DE-D59D37EC79D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "8B8805A0-F543-450D-82E9-EE923904E2A8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.21:*:*:*:*:*:*:*",
              "matchCriteriaId": "58779045-578C-41D5-9CAE-D6F48C91654C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.22:*:*:*:*:*:*:*",
              "matchCriteriaId": "969F18EF-067A-47BA-9DC4-9FA69D9DCBB7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.23:*:*:*:*:*:*:*",
              "matchCriteriaId": "E12766AB-2AFE-4BBD-8B80-8BEA932ABDFE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.24:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C2C7514-8BB4-4B8A-A5AF-D4A26B232597",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.25:*:*:*:*:*:*:*",
              "matchCriteriaId": "64C0AB94-ED91-4218-8F97-862BA57D1CC8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.26:*:*:*:*:*:*:*",
              "matchCriteriaId": "E2FF5C05-0A64-416C-8346-EE5FF4AA14F2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.27:*:*:*:*:*:*:*",
              "matchCriteriaId": "5C081128-2846-4257-B822-10AADE54899D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.28_r2:*:*:*:*:*:*:*",
              "matchCriteriaId": "45FF1704-80C6-439E-B145-7F5B14B62E46",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.2.29_rev_1.134:*:*:*:*:*:*:*",
              "matchCriteriaId": "7D92C2EA-951D-485B-8653-528926E55557",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.3.27_2.20061018:*:*:*:*:*:*:*",
              "matchCriteriaId": "548AE94B-CFF5-4416-812B-B1F60C2799F7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.3.28_2.20061022:*:*:*:*:*:*:*",
              "matchCriteriaId": "55399875-38F4-486B-88F2-E17F00C901CF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.3.28_20061022:*:*:*:*:*:*:*",
              "matchCriteriaId": "8971D9E4-C4B7-4DFF-B20D-0520D484E692",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.3.28_e1.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "86033CDB-D9A3-4872-9FF7-789F2332923B",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors that prevent the array from being null terminated."
    },
    {
      "lang": "es",
      "value": "slapo-pcache (overlays/pcache.c) en slapd en OpenLDAP versiones anteriores a 2.3.39, cuando es ejecutado como un servidor de almacenamiento en cach\u00e9 de proxy, asigna memoria mediante una variante malloc en lugar de calloc, lo que impide que una matriz se inicialice apropiadamente y podr\u00eda permitir a atacantes causar una denegaci\u00f3n de servicio (fallo de segmentaci\u00f3n) por medio de vectores de ataque desconocidos que impiden que la matriz sea terminada en null."
    }
  ],
  "id": "CVE-2007-5708",
  "lastModified": "2025-04-09T00:30:58.490",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "MEDIUM",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 7.1,
          "confidentialityImpact": "NONE",
          "integrityImpact": "NONE",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 8.6,
        "impactScore": 6.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2007-10-30T19:46:00.000",
  "references": [
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27424"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27683"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27756"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27868"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29225"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29461"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29682"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://security.gentoo.org/glsa/glsa-200803-28.xml"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.debian.org/security/2008/dsa-1541"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:058"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5163"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Patch"
      ],
      "url": "http://www.openldap.org/lists/openldap-announce/200710/msg00001.html"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.redhat.com/archives/fedora-package-announce/2007-November/msg00460.html"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.securityfocus.com/bid/26245"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.ubuntu.com/usn/usn-551-1"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2007/3645"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27424"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27683"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27756"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/27868"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29225"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29461"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29682"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://security.gentoo.org/glsa/glsa-200803-28.xml"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.debian.org/security/2008/dsa-1541"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:058"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.novell.com/linux/security/advisories/2007_24_sr.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5163"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "http://www.openldap.org/lists/openldap-announce/200710/msg00001.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.redhat.com/archives/fedora-package-announce/2007-November/msg00460.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/26245"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.ubuntu.com/usn/usn-551-1"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2007/3645"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com",
  "vendorComments": [
    {
      "comment": "Not vulnerable. This issue did not affect the versions of OpenLDAP as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
      "lastModified": "2007-11-01T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…