CVE-2015-6908
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
- Openldap
- ≤ 2.4.42
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 20.0% (97th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2015-09-11
CVE-2015-6908 at NVD
2 known exploits for CVE-2015-6908
Proof-of-concept code and exploit modules indexed by Sploitus