Vulnerability record · CVE-2006-5779 · published 7 November 2006
CVE-2006-5779: OpenLDAP assertion failure crash via long BIND authcid
Openldap · Openldap
OpenLDAP before 2.3.29 crashes when it receives an LDAP BIND request carrying an overly long authcid name, tripping an assertion failure in the daemon. Because the flaw is reachable over the network without credentials, any exposed LDAP listener can be knocked offline by a single malformed request.
Description
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote crash of a core directory service with public exploit references and very high EPSS, though impact is limited to availability.
What it is
OpenLDAP before 2.3.29 crashes when it receives an LDAP BIND request carrying an overly long authcid name, tripping an assertion failure in the daemon. Because the flaw is reachable over the network without credentials, any exposed LDAP listener can be knocked offline by a single malformed request.
Impact
An unauthenticated remote attacker can terminate the slapd process, causing a denial of service for all directory-dependent authentication and lookups until the service is restarted.
Attack surface
Reached over the network via the LDAP protocol on the directory listener; the CVSS vector shows no privileges and no user interaction required, so a single crafted BIND request suffices.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.759, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade OpenLDAP to 2.3.29 or later, or apply the vendor patch for your distribution (Ubuntu USN-384-1, Gentoo GLSA 200611-25, OpenPKG SA-2006.033).
- Restrict LDAP listener exposure to trusted networks with firewall rules or bind to internal interfaces only.
- Run slapd under a supervisor or service manager that automatically restarts it, and alert on unexpected restarts.
- Enforce a maximum length on authcid values at any LDAP proxy or load balancer in front of slapd.
- Monitor vendor advisories for the affected distribution and confirm the installed package version is patched.
Detection
- Alert on slapd process crashes or unexpected restarts and correlate them with inbound LDAP BIND traffic.
- Inspect LDAP BIND request logs or packet captures for abnormally long authcid fields.
- Watch for repeated BIND attempts from a single source or bursts of malformed LDAP requests.
- Baseline normal BIND request sizes and flag outliers that precede a daemon termination.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5779 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5779), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.