Files
cve/2011/CVE-2011-4079.md

23 lines
953 B
Markdown
Raw Permalink Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2011-4079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4079)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
2025-09-29 21:09:30 +02:00
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
2024-05-26 14:27:05 +02:00
### Description
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.
### POC
#### Reference
No PoCs from references.
#### Github
2024-07-25 21:25:12 +00:00
- https://github.com/1karu32s/dagda_offline
2024-05-26 14:27:05 +02:00
- https://github.com/MrE-Fog/dagda
- https://github.com/bharatsunny/dagda
2025-09-29 21:09:30 +02:00
- https://github.com/dbeltran24/Dagda
2024-05-26 14:27:05 +02:00
- https://github.com/eliasgranderubio/dagda
- https://github.com/man151098/dagda