在 OpenBSD 7.8(errata 057 之前)和 7.9(errata 021 之前)中的 ldapd 服务中,委托的 BSD 认证结果仅通过 LDAP 子进程的客户端文件描述符和 LDAP 消息 ID 进行关联。当连接关闭后,后续重用相同文件描述符和消息 ID 的新连接可能会接收到之前已完成的认证结果。能够访问 ldapd 的远程攻击者可以利用此缺陷,以其他身份完成 Bind(绑定)操作。此外,连接缺失还可能导致空指针解引用漏洞。(注意:ldapd 默认未启用。)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet