CVE-2015-0283

The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
redhatslapi-nis
𝑥
≤ 0.54.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
slapi-nis
bookworm
0.60.0-1
fixed
bullseye
0.56.5-2
fixed
sid
0.60.0-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
slapi-nis
artful
ignored
bionic
not-affected
cosmic
not-affected
lucid
dne
precise
dne
trusty
dne
utopic
dne
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-admintools
RHEL 7
0:4.1.0-18.el7_1.3
fixed
ipa-client
RHEL 7
0:4.1.0-18.el7_1.3
fixed
ipa-python
RHEL 7
0:4.1.0-18.el7_1.3
fixed
ipa-server
RHEL 7
0:4.1.0-18.el7_1.3
fixed
ipa-server-trust-ad
RHEL 7
0:4.1.0-18.el7_1.3
fixed
slapi-nis
RHEL 7
0:0.54-3.el7_1
fixed
Common Weakness Enumeration