Description
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).
References (8)
Scores
EPSS
0.0028
EPSS Percentile
51.5%
Details
CWE
CWE-824
Status
published
Products (1)
openldap/openldap
< 2.1.12
Published
Mar 20, 2003
Tracked Since
Feb 18, 2026