Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 604783 - (CVE-2010-2222) CVE-2010-2222 redhat-ds/389: null deref in _ger_parse_control() for subjectdn can crash server
CVE-2010-2222 redhat-ds/389: null deref in _ger_parse_control() for subjectdn...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20100701,repo...
: Security
Depends On: 603942
Blocks: 1248117
  Show dependency treegraph
 
Reported: 2010-06-16 13:59 EDT by Vincent Danen
Modified: 2016-03-04 05:39 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-12-22 05:49:21 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
patch to correct the flaw (1.79 KB, patch)
2010-06-16 14:06 EDT, Vincent Danen
no flags Details | Diff

  None (edit)
Description Vincent Danen 2010-06-16 13:59:32 EDT
A vulnerability in Red Hat Directory Server and the 389 Directory Server was discovered.  The code that parses the GER request (_ger_parse_control()) can dereference a NULL pointer.  An unauthenticated user able to communicate with the Directory Server could use a crafted search query that would cause the Directory Server to crash.

This issue has been assigned the name CVE-2010-2222.
Comment 2 Vincent Danen 2010-06-16 14:06:12 EDT
Created attachment 424540 [details]
patch to correct the flaw
Comment 3 Tomas Hoger 2010-07-01 14:56:24 EDT
Lifting embargo.

This bug was only introduced recently in the following commit:
http://git.fedorahosted.org/git/?p=389/ds.git;a=commitdiff;h=78c50664d6#patch10

Therefore, this issue did not affect any released version of Red Hat Directory Server.
Comment 4 Tomas Hoger 2010-07-02 02:52:20 EDT
(In reply to comment #2)
> Created an attachment (id=424540) [details]
> patch to correct the flaw    

Committed to git:
http://git.fedorahosted.org/git/?p=389/ds.git;a=commitdiff;h=82625ebf67

Note You need to log in before you can comment on or make changes to this bug.