CVE-2015-6908
Openldap < 2.4.42 - Improper Input Validation
Title source: ruleDescription
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
Exploits (1)
References (17)
Scores
EPSS
0.7051
EPSS Percentile
98.7%
Details
CWE
CWE-20
Status
published
Products (2)
apple/mac_os_x
< 10.11.1
openldap/openldap
< 2.4.42
Published
Sep 11, 2015
Tracked Since
Feb 18, 2026