[3.5] openldap: Double free vulnerability in servers/slapd/back-mdb/search.c (CVE-2017-9287)
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a
double free vulnerability. A user with access to search the
directory can crash slapd by issuing a search including the Paged
Results control with a page size of 0.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2017-9287
Patch:
(from redmine: issue id 7363, created on 2017-06-01, closed on 2017-06-15)
- Relations:
- parent #7360 (closed)
- Changesets:
- Revision 98cfa8f1 by Natanael Copa on 2017-06-15T09:53:40Z:
main/openldap: sec fix for CVE-2017-9287
fixes #7363