ubuntu · CVE-2015-1545

Quick triage

Priority: low Published: 2015-02-12 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-1545 low priority: Ubuntu including 1 source packages (openldap), 6 status rows across 6 suites (lucid, precise, trusty, upstream, utopic, vivid): released 5, ignored 1.

Description:

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

cvelogic Threat Intelligence