CVE-2013-4449: Medium severity macos catalina vulnerability
It was discovered that OpenLDAP, with the rwm overlay to slapd, could segfault if a user were able to query the directory and immediately unbind from the server. This seems to be due to the rwm overlay not doing reference counting properly, so rwmconndestroy frees the session context while rwmopsearch is using it. This condition also seems to require multiple cores/CPUs to trigger.
This was also reported upstream [1] and is currently unfixed.
[1] http://www.openldap.org/its/index.cgi/Incoming?id=7723
Other sources
OpenLDAP. Multiple issues were addressed by updating to OpenLDAP version 2.4.28.
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwmconndestroy to free the session context while it is being used by rwmopsearch.
— Debian
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is the severity of CVE-2013-4449?
The severity of CVE-2013-4449 is high.
How do I fix CVE-2013-4449 on macOS Catalina?
To fix CVE-2013-4449 on macOS Catalina, update to OpenLDAP version 2.4.28 or later.
How do I fix CVE-2013-4449 on macOS Mojave?
To fix CVE-2013-4449 on macOS Mojave, update to OpenLDAP version 2.4.28 or later.
How do I fix CVE-2013-4449 on macOS High Sierra?
To fix CVE-2013-4449 on macOS High Sierra, update to OpenLDAP version 2.4.28 or later.
Where can I find more information about CVE-2013-4449?
You can find more information about CVE-2013-4449 at the following reference: [Apple Support](https://support.apple.com/en-us/HT210788)