SB2020010323 - Off-by-one in OpenLDAP
Published: January 3, 2020 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Off-by-one (CVE-ID: CVE-2014-8182)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
Remediation
Install update from vendor's website.