CVE-2012-1164: Openldap

Low severity, CVSS 2.6. EPSS: 3.6% chance of exploitation in the next 30 days.

slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.

Affected products

  • Openldap Openldap: up to and including 2.4.29; version 2.4.6 only; version 2.4.7 only; version 2.4.8 only; version 2.4.9 only; version 2.4.10 only; …

Published 2012-06-29. Last modified 2026-06-16.