Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25692

Опубликовано: 19 окт. 2020
Источник: redhat
CVSS3: 7.5

Описание

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

A NULL pointer dereference flaw was found in the OpenLDAP server, during a request for renaming RDNs. This flaw allows a remote, unauthenticated attacker to crash the slapd process by sending a specially crafted request, causing a denial of service. The highest threat from this vulnerability is to system availability.

Отчет

This vulnerability affects the server side only. As a result, OpenLDAP client components, such as the component shipped in Red Hat Enterprise Linux 8, are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapOut of support scope
Red Hat Enterprise Linux 5openldap24-libsNot affected
Red Hat Enterprise Linux 6compat-openldapNot affected
Red Hat Enterprise Linux 6openldapOut of support scope
Red Hat Enterprise Linux 7compat-openldapNot affected
Red Hat Enterprise Linux 8openldapNot affected
Red Hat JBoss Core ServicesopenldapNot affected
Red Hat JBoss Enterprise Application Platform 5openldapNot affected
Red Hat JBoss Enterprise Web Server 2openldapNot affected
Red Hat Enterprise Linux 7openldapFixedRHSA-2021:138927.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1894567openldap: NULL pointer dereference for unauthenticated packet in slapd

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

CVSS3: 7.5
nvd
около 5 лет назад

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

CVSS3: 7.5
msrc
около 5 лет назад

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55 during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request causing a Denial of Service.

CVSS3: 7.5
debian
около 5 лет назад

A NULL pointer dereference was found in OpenLDAP server and was fixed ...

suse-cvrf
около 5 лет назад

Security update for openldap2

7.5 High

CVSS3