CVE-2015-1545: Openldap

Medium severity, CVSS 5.0. EPSS: 11.1% chance of exploitation in the next 30 days.

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

Affected products

  • Openldap Openldap: version 2.4.13 only; version 2.4.14 only; version 2.4.15 only; version 2.4.16 only; version 2.4.17 only; version 2.4.18 only; …

Published 2015-02-12. Last modified 2026-06-17.