>> OpenLDAP ASN.1 BER Decoding Denial of Service Vulnerability
Title : OpenLDAP ASN.1 BER Decoding Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-1978 CVE ID : CVE-2008-2952 CWE ID : CWE-617
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-01
Technical Description
A vulnerability has been identified in OpenLDAP, which could be exploited by attackers to cause a denial of service. This issue is caused by an "assert()" error in the "ber_get_next()" [libraries/liblber/io.c] function when handling ASN.1 BER network datagrams with an incorrect size of a BerElement, which could be exploited by unauthenticated attackers to terminate a vulnerable application, creating a denial of service condition.