RULE(RULE ID:2105148)

Rule General Information
Release Date: 2016-08-18
Rule Name: PROTOCOL-LDAP Openldap Slapd Deref Overlay Null Pointer Dereference Vulnerability (CVE-2015-1545)
Severity:
CVE ID:
Rule Protection Details
Description: The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:72519
SecurityTrackerID:1032399
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.openldap.org/devel/gitweb.cgi?p=openldap.git