CVE-2013-0336
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.
- Affected products
- 389 Directory Server, Freeipa
- Redhat Freeipa
- ≤ 3.1.5, 3.0.0, 3.0.1, 3.0.2, 3.1.1, 3.1.2, 3.1.3, 3.1.4
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 2.8% (85th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2014-11-03
CVE-2013-0336 at NVD
No indexed exploits for CVE-2013-0336 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-0336 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.