Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-6493

EPSS 8.43% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-6493

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenLDAP服务器Kerberos Bind请求远程栈溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的自由和开源实现,它已被包含在Linux发行版中。 OpenLDAP在处理Kerberos Bind请求时存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞在服务器上执行任意指令。 OpenLDAP代码的servers/slapd/kerberos.c文件中的krbv4_ldap_auth函数存在缓冲区溢出漏洞,该函数处理指定了LDAP_AUTH_KRBV41认证方式的LDAP bind请求,cred变量包含有指向客户端所发送Kerb
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-6493

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-6493

Please Login to view more intelligence information

Same Patch Batch · n/a · 2006-12-13 · 8 CVEs total

CVE-2006-6496CA Anti-Virus'vetfddnt.sys和vetmonnt.sys'驱动本地拒绝服务漏洞
CVE-2006-2386Microsoft Outlook Express地址簿处理远程任意指令执行漏洞(MS06-076)
CVE-2006-4702Microsoft Windows Media Format运行时库远程任意指令执行漏洞(MS06-078)
CVE-2006-5584Microsoft Windows远程安装服务远程任意指令执行漏洞(MS06-077)
CVE-2006-5585Microsoft Windows文件名单处理本地权限提升漏洞(MS06-075)
CVE-2006-6494Sun Solaris 'ld.so'多个本地安全漏洞
CVE-2006-6495Sun Solaris ld.so多个本地安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-6493

No comments yet


Leave a comment