Impact
The vulnerability is a use‑after‑free flaw in the Apache HTTP Server mod_ldap module that is triggered by per‑directory configuration. The flaw may allow an attacker to trigger memory corruption during LDAP processing, which could result in arbitrary code execution or cause a denial of service. The weakness is identified as CWE‑416. The CVSS score is 9.8.
Affected Systems
Apache HTTP Server supplied by the Apache Software Foundation is affected from version 2.4.0 up to and including 2.4.67. Any installation using the mod_ldap module in per‑directory contexts within that version range is vulnerable.
Risk and Exploitability
EPSS score is < 1%, indicating a low probability of exploitation, but exposure is still uncertain because the vulnerability is not listed in the CISA KEV catalog. Because the flaw is a use‑after‑free in mod_ldap, an attacker would need to craft a request that triggers the module in a per‑directory context; successful exploitation could allow arbitrary code execution on the web server with the privileges of the HTTPd process. The CVSS score of 9.8 reflects a high severity risk.
OpenCVE Enrichment
Debian DLA