CVE-2012-3429

UnknownEPSS 3.07%

Last modified

CVE-2012-3429 is a vulnerability of currently unknown severity. The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.. EPSS estimates a 3.07% chance of exploitation in the next 30 days.

Description

The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.

Metrics

EPSS Probability
3.07%

86.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Martin NagyBind-Dyndb-Ldap<= 1.1.0Rc1
Martin NagyBind-Dyndb-Ldap0.1.0A1
Martin NagyBind-Dyndb-Ldap0.2.0
Martin NagyBind-Dyndb-Ldap1.0.0B1
Martin NagyBind-Dyndb-Ldap1.1.0A1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3429?
The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.
How severe is CVE-2012-3429?
Severity scoring for CVE-2012-3429 is pending analysis. The EPSS model estimates a 3.07% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3429?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-3429?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST