Padl Software nss_ldap Local Denial...

- AV AC AU C I A
发布: 2000-10-27
修订: 2025-04-13

nss_ldap is a module offered by Padl Software that allows a system to use LDAP directories as the source of information for user attributes (via getpwent, etc) and related data. A local denial of service condition is possible when nss_ldap is in use with nscd (name service caching daemon), as is the case in RedHat Linux 7.0,6.2 and 6.1 with LDAP support. Nscd is a multithreaded daemon program that processes these lookups before they are sent to nss_ldap. If an attacker makes a large number of LDAP information requests, moreso than threads nscd can handle, then they and all further requests can be blocked until the system is reset or the nscd process is killed. This can be a very effective local denial of service attack. The reason for this condition is mutual dependence of two components on resources being free and blocking until this is the case. The problem occurs in a situation where nscd is very busy and all threads are in use (an attacker can of course create this...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息