Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
| Software | From | Fixed in |
|---|---|---|
| openldap / openldap | 2.4.40 | 2.4.40.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| apple / mac_os_x | 10.10.2 | 10.10.2.x |