Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-0212

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的自由和开源实现,它已被包含在Linux发行版中。 OpenLDAP 2.4.22版本存在漏洞。OpenLDAP的schema_init.c文件的IA5StringNormalize函数没有检查smr_normalize函数返回值存在空指针引用错误,远程攻击者可以借助零长度RDN destination字符串的modrdh调用导致服务拒绝(崩溃)。

AI Predicted 7.5 Difficulty: Trivial EPSS 5.98% · P93
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-0212

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
OpenLDAP modrdn请求空指针引用漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的自由和开源实现,它已被包含在Linux发行版中。 OpenLDAP 2.4.22版本存在漏洞。OpenLDAP的schema_init.c文件的IA5StringNormalize函数没有检查smr_normalize函数返回值存在空指针引用错误,远程攻击者可以借助零长度RDN destination字符串的modrdh调用导致服务拒绝(崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-0212

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0212

登录查看更多情报信息。

Vendor Advisories for CVE-2010-0212 (13)

Mailing List Discussions for CVE-2010-0212 (2)

Other References for CVE-2010-0212 (2)

Same Patch Batch · n/a · 2010-07-27 · 27 CVEs total

CVE-2009-4962 Adammo Fat Player栈缓冲区溢出漏洞
CVE-2009-4974 Sweetphp TotalCalendar 'box_display.php'目录遍历漏洞
CVE-2009-4973 Sweetphp TotalCalendar 'rss.php'SQL注入漏洞
CVE-2009-4972 SimpleID 'index.php'跨站脚本攻击漏洞
CVE-2009-4971 TYPO3 AJAX Chat扩展件未明SQL注入漏洞
CVE-2009-4970 TYPO3 t3m_affiliate扩展件未明SQL注入漏洞
CVE-2009-4969 TYPO3 Solidbase Bannermanagement扩展件未明SQL注入漏洞
CVE-2009-4968 TYPO3 Event Registration扩展件未明SQL注入漏洞
CVE-2009-4967 TYPO3 Car扩展件未明SQL注入漏洞
CVE-2009-4966 TYPO3 AST ZipCodeSearch扩展件未明SQL注入漏洞
CVE-2009-4965 TYPO3 AIRware Lexicon跨站件SQL注入漏洞
CVE-2009-4964 Ksplayer KSP 2006 FINAL栈缓冲区溢出漏洞
CVE-2009-4963 TYPO3 Commerce扩展件跨站脚本攻击漏洞
CVE-2010-0211 OpenLDAP modrdn请求内存破坏漏洞
CVE-2009-4961 Lanai Core默认配置信息泄露漏洞
CVE-2009-4960 Lanai Core 'modules/backup/download.php'目录遍历漏洞
CVE-2009-4959 TYPO3 TT3M E-Mail Marketing工具扩展件SQL注入漏洞
CVE-2009-4958 EMO Breader Manager 'video.php'SQL注入漏洞
CVE-2010-2704 HP OpenView网络节点管理器ov.dll库远程溢出漏洞
CVE-2010-2703 HP OpenView网络节点管理器ov.dll库execvp_nc函数远程栈溢出漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-0212

No comments yet


Leave a comment