Unrated severityNVD Advisory· Published Sep 11, 2015· Updated May 6, 2026
CVE-2015-6908
CVE-2015-6908
Description
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.openldap.org/its/index.cgi/Software%20BugsnvdExploitVendor Advisory
- lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1840.htmlnvd
- www.debian.org/security/2015/dsa-3356nvd
- www.openldap.org/devel/gitweb.cginvd
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlnvd
- www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlnvd
- www.security-assessment.com/files/documents/advisory/OpenLDAP-ber_get_next-Denial-of-Service.pdfnvd
- www.securityfocus.com/bid/76714nvd
- www.securitytracker.com/id/1033534nvd
- www.ubuntu.com/usn/USN-2742-1nvd
- support.apple.com/HT205637nvd
News mentions
0No linked articles in our index yet.