Critical severity9.8NVD Advisory· Published Jul 28, 2010· Updated Apr 29, 2026
CVE-2010-0211
CVE-2010-0211
Description
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
Affected products
6Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.openldap.org/its/index.cgi/Software%20BugsnvdExploit
- www.securityfocus.com/bid/41770nvdBroken LinkExploitPatchThird Party AdvisoryVDB Entry
- kb.juniper.net/InfoCenter/indexnvdThird Party Advisory
- secunia.com/advisories/40639nvdBroken LinkVendor Advisory
- secunia.com/advisories/40677nvdBroken LinkVendor Advisory
- secunia.com/advisories/40687nvdBroken LinkVendor Advisory
- security.gentoo.org/glsa/glsa-201406-36.xmlnvdThird Party Advisory
- www.securityfocus.com/archive/1/515545/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.vmware.com/security/advisories/VMSA-2011-0001.htmlnvdThird Party Advisory
- www.vupen.com/english/advisories/2010/1849nvdBroken LinkVendor Advisory
- www.vupen.com/english/advisories/2010/1858nvdBroken LinkVendor Advisory
- lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlnvdMailing List
- lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlnvdMailing List
- secunia.com/advisories/42787nvdBroken Link
- support.apple.com/kb/HT4435nvdIssue Tracking
- www.redhat.com/support/errata/RHSA-2010-0542.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0543.htmlnvdBroken Link
- www.vupen.com/english/advisories/2011/0025nvdBroken Link
News mentions
0No linked articles in our index yet.