Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2953

Опубликовано: 29 мая 2023
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

A vulnerability was found in OpenLDAP, in ber_memalloc_x() function, leading to a null pointer dereference. This flaw can result in reduced system memory and cause LDAP authentication failures. The impact is primarily a disruption in authentication processes, which may hinder user access or service operations relying on LDAP for authentication.

Отчет

This vulnerability is rated as a low severity because, it affects only systems where memory exhaustion might occur due to mishandling of users crafted inputs, and it requires an authenticated user to trigger the issue. This vulnerability does not affect any versions of RHEL above 9.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-openldapOut of support scope
Red Hat Enterprise Linux 6openldapOut of support scope
Red Hat Enterprise Linux 7compat-openldapOut of support scope
Red Hat Enterprise Linux 7openldapOut of support scope
Red Hat Enterprise Linux 9openldapAffected
Red Hat Enterprise Linux 8openldapFixedRHSA-2024:426402.07.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportopenldapFixedRHSA-2024:603329.08.2024
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsopenldapFixedRHSA-2025:817627.05.2025
Red Hat Enterprise Linux 9.2 Extended Update SupportopenldapFixedRHSA-2025:818127.05.2025

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2210651openldap: null pointer dereference in ber_memalloc_x function

EPSS

Процентиль: 80%
0.01456
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS3: 7.5
nvd
около 2 лет назад

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
около 2 лет назад

A vulnerability was found in openldap. This security flaw causes a nul ...

suse-cvrf
около 2 лет назад

Security update for openldap2

EPSS

Процентиль: 80%
0.01456
Низкий

7.1 High

CVSS3