CVE-2010-0211 is a critical denial-of-service and potential arbitrary code execution vulnerability affecting OpenLDAP 2.4.22 and products like Apple, openSUSE, and VMware that incorporate it. The flaw stems from a missing return value check in the slap_modrdn2mods function, allowing remote attackers to trigger a segmentation fault and free an uninitialized pointer via malformed RDN strings in modrdn calls. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication, leading to high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or showing active exploitation, a proof-of-concept exploit exists on ExploitDB, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.22CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:* | ||
>= 10.6.0, < 10.6.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.