23334Third-party advisory
http://secunia.com/advisories/23334 CVE-2006-6493
OpenLDAP 2.4.3 - 'KBIND' Remote Buffer Overflow
Record summary
CVE-2006-6493 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenLDAP 2.4.3 - 'KBIND' Remote Buffer OverflowExploitDB exploitby Solar EclipseNot analyzed1 file
References
62023Third-party advisory
http://securityreason.com/securityalert/2023 phreedom.org
http://www.phreedom.org/solar/exploits/openldap-kbind 20061212 OpenLDAP kbind authentication buffer overflowmailing list
http://www.securityfocus.com/archive/1/454181/30/0/threaded ADV-2006-4964vdb entry
http://www.vupen.com/english/advisories/2006/4964 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6493