CVE-2010-4746

389 Directory Server <1.2.7.5 - DoS

Title source: llm
STIX 2.1

Description

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.

References (2)

Core 2
Core References

Scores

EPSS 0.0166
EPSS Percentile 74.2%

Details

CWE
CWE-399
Status published
Products (7)
fedoraproject/389_directory_server 1.2.1
fedoraproject/389_directory_server 1.2.2
fedoraproject/389_directory_server 1.2.3
fedoraproject/389_directory_server 1.2.5 (5 CPE variants)
fedoraproject/389_directory_server 1.2.6 (9 CPE variants)
fedoraproject/389_directory_server 1.2.6.1
fedoraproject/389_directory_server < 1.2.7
Published Feb 23, 2011
Tracked Since Feb 18, 2026