CVE-2018-1000121
Description
A NULL pointer dereference in curl's LDAP code (versions 7.21.0 to 7.58.0) allows a remote attacker to cause a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A NULL pointer dereference in curl's LDAP code (versions 7.21.0 to 7.58.0) allows a remote attacker to cause a denial of service.
Vulnerability
A NULL pointer dereference vulnerability exists in the LDAP code of curl versions 7.21.0 through 7.58.0 [1][2][3][4]. The flaw occurs when curl processes specially crafted LDAP URL responses, leading to a crash if the returned data triggers the vulnerable code path without proper validation.
Exploitation
An attacker can exploit this vulnerability by sending a malicious LDAP URL or response to a system using curl (or libcurl) to perform LDAP operations. No authentication or special privileges are required; the attack can be conducted remotely, as the vulnerable functionality is triggered by processing the LDAP response. The attacker only needs to cause the application to make a request that results in a crafted LDAP reply.
Impact
Successful exploitation leads to a denial of service (DoS) due to the NULL pointer dereference, causing the application or service using curl to crash. This impacts availability (C) and potentially integrity (I) or confidentiality (A) if the crash disrupts normal operations. The CVSS score is moderate, as detailed in the Red Hat advisories [1][2].
Mitigation
Red Hat has released updated packages to fix this vulnerability in various software collections and base operating system versions. For Red Hat Software Collections (httpd24), the fix is included in curl 7.61.1, available via RHSA-2018:3558 [1]. For Red Hat Enterprise Linux 7, the fix is included in curl updates via RHSA-2018:3157 [2]. Additionally, later updates (RHSA-2020:0544 and RHSA-2020:0594 [3][4]) address the issue for other products. Users should apply the relevant updates as soon as possible. If patching is not immediately possible, limiting LDAP functionality or restricting network access to untrusted LDAP servers can reduce risk.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
19- osv-coords18 versionspkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/curl-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/curl-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/curl-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITY
< 7.37.0-37.17.1+ 17 more
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-37.17.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-70.27.1
- (no CPE)range: < 7.37.0-70.27.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
16- access.redhat.com/errata/RHBA-2019:0327mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3157mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3558mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2020:0544mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2020:0594mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/3598-1/mitrevendor-advisoryx_refsource_UBUNTU
- usn.ubuntu.com/3598-2/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2018/dsa-4136mitrevendor-advisoryx_refsource_DEBIAN
- www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlmitrex_refsource_CONFIRM
- www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlmitrex_refsource_CONFIRM
- www.securityfocus.com/bid/103415mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1040529mitrevdb-entryx_refsource_SECTRACK
- curl.haxx.se/docs/adv_2018-97a2.htmlmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2018/03/msg00012.htmlmitremailing-listx_refsource_MLIST
- www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlmitrex_refsource_CONFIRM
- www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.