Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46823

Опубликовано: 18 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

A flaw was found in python-ldap. The vulnerability occurs due to a regular expression and leads to a denial of service attack. This flaw allows an attacker to parse LDAP schema definitions from an untrusted source, leading to a crash or code execution.

Отчет

Red Hat Enterprise Linux 9.0.z is affected by this vulnerability as it includes the vulnerable version of python-ldap (3.3.1). However, the issue was resolved in Red Hat Enterprise Linux 9.2 and later via RHEA-2023:2359, which rebased python-ldap to version 3.4.3 containing the upstream fix. Red Hat Enterprise Linux 10 is not affected, as it does not ship the vulnerable code.

Меры по смягчению последствий

Check input for an excessive amount of backslashes in schemas. More than a dozen backslashes per line are atypical.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2python-ldapAffected
Red Hat Ansible Tower 3python-ldapAffected
Red Hat Enterprise Linux 6python-ldapOut of support scope
Red Hat Enterprise Linux 7python-ldapOut of support scope
Red Hat Enterprise Linux 8python-ldapWill not fix
Red Hat Enterprise Linux 9python-ldapWill not fix
Red Hat OpenStack Platform 13 (Queens)python-ldap3Out of support scope
Red Hat OpenStack Platform 16.1python-ldap3Not affected
Red Hat OpenStack Platform 16.2python-ldap3Not affected
Red Hat Quay 3quay/quay-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-186
https://bugzilla.redhat.com/show_bug.cgi?id=2044615python-ldap: Regular expression denial of service in LDAP schema parser

EPSS

Процентиль: 74%
0.00812
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVSS3: 6.5
nvd
больше 3 лет назад

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVSS3: 6.5
msrc
больше 3 лет назад

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVSS3: 6.5
debian
больше 3 лет назад

python-ldap before 3.4.0 is vulnerable to a denial of service when lda ...

CVSS3: 6.5
github
больше 3 лет назад

Denial of Service in python-ldap

EPSS

Процентиль: 74%
0.00812
Низкий

6.5 Medium

CVSS3