CVE-2011-1081
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDMar 20
1st PoCJan 3
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/35445⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://openwall.com/lists/oss-security/2011/02/28/1http://openwall.com/lists/oss-security/2011/02/28/2http://openwall.com/lists/oss-security/2011/03/01/11http://openwall.com/lists/oss-security/2011/03/01/15https://bugzilla.novell.com/show_bug.cgi?id=674985https://bugzilla.redhat.com/show_bug.cgi?id=680975http://secunia.com/advisories/43331http://secunia.com/advisories/43718http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://securitytracker.com/id?1025191https://exchange.xforce.ibmcloud.com/vulnerabilities/66239