Impact
Stack overflow vulnerability in the Apache Directory LDAP API allows an unauthenticated client to send a deeply nested search filter before binding, which overflows the stack in the server's decoder. This flaw can lead to application crashes, resulting in a denial of service. The flaw is classified as CWE-121.
Affected Systems
The affected product is Apache Software Foundation’s Apache Directory LDAP API, versions 1.2.0 through 1.2.8. Users running any of these releases are vulnerable. The list of affected versions is explicitly tied to the 1.2 series and excludes 1.2.9 and later.
Risk and Exploitability
The vulnerability is remotely exploitable by any network client that can contact the LDAP service before authentication. The overflow can cause a crash in the server, leading to a denial of service. The likely attack vector is an unauthenticated client sending a deeply nested filter before binding; this inference is based on the description. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is currently no publicly known exploit or payload for this issue.
OpenCVE Enrichment