« Volver al listado

CVE-2010-0211

Estado: ModificadaCrítica (9.8)—💥 Exploit

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0211",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-07-28T12:48:51.620",
  "references": [
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html",
      "tags": [
        "Mailing List"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html",
      "tags": [
        "Mailing List"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/40639",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/40677",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/40687",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/42787",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://support.apple.com/kb/HT4435",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570",
      "tags": [
        "Exploit"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0542.html",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/515545/100/0/threaded",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/41770",
      "tags": [
        "Broken Link",
        "Exploit",
        "Patch",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1024221",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0001.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1849",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1858",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0025",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/40639",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/40677",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/40687",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42787",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4435",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0542.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/515545/100/0/threaded",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/41770",
      "tags": [
        "Broken Link",
        "Exploit",
        "Patch",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1024221",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0001.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1849",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1858",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0025",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-252"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite."
    },
    {
      "lang": "es",
      "value": "La función slap_modrdn2mods en modrdn.c en OpenLDAP v2.4.22 no comprueba el valor de retorno de la llamada a la función smr_normalize, lo que permite a atacantes remotos provocar una denegación de servicio (fallo de segmentación) y posiblemente ejecución de comandos de su elección a través de una llamada a modrdn call con una cadena RDN que contenga secuencias UTF-8 inválidas, lo que provocará la liberación de un puntero no válido ni inicializado en la función slap_mods_free,  como se demostró usando la suite de test Codenomicon LDAPv3."
    }
  ],
  "lastModified": "2026-06-16T23:15:43.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FAEA812-BB47-47A3-A975-B3B8D30DBA36"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13771B15-CD71-472A-BE56-718B87D5825D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BDE707D-A1F4-4829-843E-F6633BB84D6D"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B42AB65-443B-4655-BAEA-4EB4A43D9509"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BB1D490-FDFB-468C-942D-0BC828B5D3F0",
              "versionEndExcluding": "10.6.5",
              "versionStartIncluding": "10.6.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65FA6685-8E50-40CA-A61D-649AECC5F48F",
              "versionEndExcluding": "10.6.5",
              "versionStartIncluding": "10.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}