https://bugs.openldap.org/show_bug.cgi?id=10488
--- Comment #1 from wangxiaomeng wangxiaomeng@kylinos.cn --- Impact Both vulnerabilities can be triggered by crafted LDAPv2 requests or legitimate operations that result in empty 'text' messages or empty referral entries. Under certain memory layouts, these out-of-bounds reads may cause the slapd service to crash (segmentation fault). Additionally, they could potentially lead to information disclosure of sensitive memory contents, depending on the system's memory layout.
Intellectual Property Statement 麒麟软件有限公司 hereby place the following modifications to OpenLDAP Software (and only these modifications) into the public domain. Hence, these modifications may be freely used and/or redistributed for any purpose with or without attribution and/or other notice. Signed-off-by: wangxiaomeng wangxiaomeng@kylinos.cn