CVE-2017-17740: McAfee Policy Auditor

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

Affected products

  • McAfee Policy Auditor: before 6.5.1 (fixed in 6.5.1)
  • Openldap Openldap: up to and including 2.4.45
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)

Published 2017-12-18. Last modified 2026-06-17.