CVE-2005-2377

Mandrakesoft Mandrake Linux - Denial of Service

Title source: rule

Description

nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote attackers to cause a denial of service (crond and other application crash) if they can cause an LDAP server to become unavailable. NOTE: it is not clear whether this attack scenario is sufficient to include this item in CVE.

Scores

EPSS 0.0074
EPSS Percentile 72.6%

Classification

Status draft

Affected Products (2)

mandrakesoft/mandrake_linux
mandrakesoft/mandrake_linux_corporate_server

Timeline

Published Jul 26, 2005
Tracked Since Feb 18, 2026