iDefense Security Advisory 03.23.07 – Remote exploitation of a design error vulnerability in Sun Microsystems Inc.’s Java System Directory Server 5.2 may cause a denial of service (DoS) condition. Due to a design error in the clean-up code following certain types of failed queries, it is possible to cause the server to call the free() function on an address obtained from uninitialized memory. This can result in an invalid memory reference leading to denial of service. iDefense has confirmed Sun Java System Directory Server 5.2 Directory Server 5.2 2005Q4 is affected by this vulnerability. Previous versions are also suspected to be vulnerable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55359/03.23.07-2.txt
Source: https://packetstormsecurity.com/files/55359/iDEFENSE-Security-Advisory-2007-03-23.2.html

