CVE-2003-1201

Severity CVSS v4.0:
Pending analysis
Type:
CWE-824 Access of Uninitialized Pointer
Publication date:
20/03/2003
Last modified:
03/04/2025

Description

ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* 2.1.12 (including)