peter bassill · operator
$ cve CVE-2010-0211 JSON

CVE-2010-0211 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 28.5% (pctl 98)

Patch early

A public exploit exists.

Description

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS28.47% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-252
On CISA KEVno
Public exploityes
Published2010-07-28
Last modified2026-06-16

Affected (5)

VendorProduct
applemac os x
applemac os x server
openldapopenldap
opensuseopensuse
vmwareesxi

Public exploits

SourceTitleDate
exploit-dbOpenLDAP 2.4.22 - 'modrdn' Multiple Vulnerabilities2010-07-19

References

→ the Explorer  ·  watch your stack  ·  NVD