Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-3429
Description:The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind- dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.
Test IDs: 1.3.6.1.4.1.25623.1.0.123849   1.3.6.1.4.1.25623.1.0.881456   1.3.6.1.4.1.25623.1.0.870800   1.3.6.1.4.1.25623.1.0.72394   1.3.6.1.4.1.25623.1.0.71445  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-3429
1027341
http://www.securitytracker.com/id?1027341
50086
http://secunia.com/advisories/50086
50159
http://secunia.com/advisories/50159
54787
http://www.securityfocus.com/bid/54787
RHSA-2012:1139
http://rhn.redhat.com/errata/RHSA-2012-1139.html
[oss-security] 20120802 bind-dyndb-ldap DoS CVE-2012-3429
http://www.openwall.com/lists/oss-security/2012/08/02/5
binddyndbldap-dnstoldapdnescape-dos(77391)
https://exchange.xforce.ibmcloud.com/vulnerabilities/77391
http://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit/?id=f345805c73c294db42452ae966c48fbc36c48006
http://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit/?id=f345805c73c294db42452ae966c48fbc36c48006
https://bugzilla.redhat.com/show_bug.cgi?id=842466
https://bugzilla.redhat.com/show_bug.cgi?id=842466




© 1998-2025 E-Soft Inc. All rights reserved.