Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15719

Опубликовано: 14 июл. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4
CVSS3: 4.2

Описание

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

eoan

ignored

end of life
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

focal

not-affected

precise/esm

not-affected

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 44%
0.00216
Низкий

4 Medium

CVSS2

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
redhat
больше 6 лет назад

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

CVSS3: 4.2
nvd
больше 5 лет назад

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

CVSS3: 4.2
debian
больше 5 лет назад

libldap in certain third-party OpenLDAP packages has a certificate-val ...

suse-cvrf
больше 5 лет назад

Security update for openldap2

suse-cvrf
больше 5 лет назад

Security update for openldap2

EPSS

Процентиль: 44%
0.00216
Низкий

4 Medium

CVSS2

4.2 Medium

CVSS3