Description
Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.
Affected products
- RedHat / directory_server7.1 – 7.1
- RedHat / directory_server7.1 – 7.1
- RedHat / directory_server7.1 – 7.1
- RedHat / directory_server7.1 – 7.1
- RedHat / directory_server7.1 – 7.1
- RedHat / directory_server8.0 – 8.0
- RedHat / fedora_directory_server1.1 – 1.1
References
- MISChttp://www.securityfocus.com/bid/29126
- MISChttp://www.securitytracker.com/id?1020001
- MISChttp://www.redhat.com/support/errata/RHSA-2008-0268.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=444712
- VENDOR_ADVISORYhttp://secunia.com/advisories/30185
- VENDOR_ADVISORYhttp://secunia.com/advisories/30181
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/42332
- MISChttp://www.redhat.com/support/errata/RHSA-2008-0269.html