CVE-2008-1677
Last modified
CVE-2008-1677 is a vulnerability of currently unknown severity. Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.. EPSS estimates a 4.93% chance of exploitation in the next 30 days.
Description
Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Directory Server | 7.1 | Sp1 |
| Redhat | Directory Server | 8.0 | — |
| Redhat | Fedora Directory Server | 1.1 | — |
References
- http://secunia.com/advisories/30181Broken Link
- http://secunia.com/advisories/30185Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0268.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0269.htmlThird Party Advisory
- http://www.securityfocus.com/bid/29126Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020001Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=444712Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42332Third Party Advisory, VDB Entry
- http://secunia.com/advisories/30181Broken Link
- http://secunia.com/advisories/30185Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0268.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0269.htmlThird Party Advisory
- http://www.securityfocus.com/bid/29126Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020001Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=444712Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42332Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1677?
How severe is CVE-2008-1677?
How do I fix CVE-2008-1677?
Are you affected by CVE-2008-1677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
