CVE-2008-2930
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.6%
from disclosure to weapon0 days
Published on NVDAug 29
1st PoCAug 27
exploitation probability
6.6%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/32304⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01532861https://bugzilla.redhat.com/show_bug.cgi?id=454065http://secunia.com/advisories/31565http://secunia.com/advisories/31627http://secunia.com/advisories/31702http://secunia.com/advisories/31867http://securitytracker.com/id?1020773https://exchange.xforce.ibmcloud.com/vulnerabilities/44733https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6078https://rhn.redhat.com/errata/RHSA-2008-0596.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00521.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00708.html