Back to Database
Status published
Medium
CVE-2006-2754
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before...
Vulnerability Description
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2754
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/305-1/
- http://www.openldap.org/devel/cvsweb.cgi/servers/slurpd/st.c.diff?r1=1.21&r2=1.22&hideattic=1&sortbydate=0&f=h
- http://secunia.com/advisories/20126
- http://secunia.com/advisories/20495
- http://www.openldap.org/devel/cvsweb.cgi/servers/slurpd/st.c?hideattic=1&sortbydate=0#rev1.22
- http://www.vupen.com/english/advisories/2006/1921
- http://www.gentoo.org/security/en/glsa/glsa-200606-17.xml
- http://www.securityfocus.com/archive/1/436674/100/0/threaded
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:096
- http://secunia.com/advisories/20685
- http://www.osvdb.org/25659
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.008-openldap.html
- http://www.openldap.org/software/release/changes.html
- http://secunia.com/advisories/20848
More from openldap
View All →CVE-2022-29155
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a...
Critical
9.8
CVE-2021-27212
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion...
High
7.5
CVE-2020-36230
A flaw was discovered in OpenLDAP before 2.4.57 leading in...
High
7.5
CVE-2020-36229
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57...
High
7.5
CVE-2020-36228
An integer underflow was discovered in OpenLDAP before 2.4.57 leading...
High
7.5
Affected Vendor
openldap
View all reports →Affected Software
openldap
Vulnerable Versions:
2.2.1, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.2.15, 2.2.16, 2.2.17, 2.2.18, 2.2.19, 2.2.20, 2.2.21
Timeline
Official Publish:
June 1st, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.