Preemptive Protection against OpenLDAP BIND Denial of Service Vulnerability
| Check Point Reference: | CPAI-2006-136 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA22750 | |
| Industry Reference(s): | CVE-2006-5779 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? OpenLDAP version 2.2.29 and prior | ||
| Vulnerability Description A denial of service vulnerability exists in OpenLDAP. OpenLDAP Software is an open source implementation of the Lightweight Directory Access Protocol (LDAP). The vulnerability could be exploited by remote attackers to crash the service or execute arbitrary code via a specially crafted LDAP request to an affected LDAP server. |
||
|
Vulnerability Details The service fails to properly process certain BIND requests due to an error in the 'libldap/getdn.c' file. Remote attackers can exploit this by sending specially crafted BIND requests to a vulnerable OpenLDAP server and causing it to crash. |
Protection Overview
Users are protected against this vulnerability if the LDAP protection for blocking multiple remote denial of service vulnerabilities addressed in the Protection section of CPAI-2006-039 has been applied.
The protection blocks specially crafted LDAP requests that may lead to a denial of service condition (DoS) on the affected LDAP server.
To configure the defense, select your product from the list below and follow the related protection steps.