CVE-2006-0647

Sun Java System Directory Server 5.2 - Denial of Service via Crafted Subtree Search Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0647. PoCs published by Evgeny Legerov.

AI-analyzed exploit summary The provided code is a stub for a DoS exploit targeting Sun ONE Directory Server. It lacks the actual payload or malformed traffic generation logic, only referencing external sample code by Evgeny Legerov.

Description

LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.

Exploits (1)

exploitdb STUB VERIFIED
by Evgeny Legerov · textdosmultiple
https://www.exploit-db.com/exploits/27171

The provided code is a stub for a DoS exploit targeting Sun ONE Directory Server. It lacks the actual payload or malformed traffic generation logic, only referencing external sample code by Evgeny Legerov.

Classification
Stub 80%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Sun ONE Directory Server
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18769
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24605
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16550
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102294-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0492
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015604

Scores

EPSS 0.0965
EPSS Percentile 94.9%

Details

Status published
Products (1)
sun/java_system_directory_server 5.2
Published Feb 13, 2006
Tracked Since Feb 18, 2026