CVE-2015-1546: Apple Mac OS X

Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.

Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.

Affected products

  • Apple Mac OS X: version 10.10.2 only
  • Openldap Openldap: version 2.4.40 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-02-12. Last modified 2026-06-17.