The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
| Software | From | Fixed in |
|---|---|---|
| openldap / openldap | - | 2.4.42.x |
| apple / mac_os_x | - | 10.11.1.x |