UBUNTU-CVE-2015-0283

Source
https://ubuntu.com/security/CVE-2015-0283
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-0283.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-0283
Upstream
Withdrawn
2025-07-18T16:43:08Z
Published
2015-03-30T14:59:00Z
Modified
2025-07-16T08:11:18.693112Z
Severity
  • Ubuntu - low
Summary
[none]
Details

The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.

References

Affected packages

Ubuntu:16.04:LTS / slapi-nis

Package

Name
slapi-nis
Purl
pkg:deb/ubuntu/slapi-nis@0.55-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.55-1

Affected versions

0.*
0.54.2-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "slapi-nis",
            "binary_version": "0.55-1"
        },
        {
            "binary_name": "slapi-nis-dbgsym",
            "binary_version": "0.55-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-0283.json"