CVE-2015-6908

Openldap < 2.4.42 - Improper Input Validation

Title source: rule

Description

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

Exploits (1)

exploitdb WORKING POC
by Denis Andzakovic · textdoslinux
https://www.exploit-db.com/exploits/38145

Scores

EPSS 0.7051
EPSS Percentile 98.7%

Details

CWE
CWE-20
Status published
Products (2)
apple/mac_os_x < 10.11.1
openldap/openldap < 2.4.42
Published Sep 11, 2015
Tracked Since Feb 18, 2026