Unrated severityNVD Advisory· Published May 18, 2021· Updated Aug 4, 2024
CVE-2020-25709
CVE-2020-25709
Description
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
Affected products
15- OpenLDAP/OpenLDAPdescription
- osv-coords14 versionspkg:bitnami/openldappkg:rpm/opensuse/openldap2&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/openldap2&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/openldap2-client-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITYpkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 2.4.56+ 13 more
- (no CPE)range: < 2.4.56
- (no CPE)range: < 2.4.46-lp151.10.24.1
- (no CPE)range: < 2.4.46-lp152.14.15.1
- (no CPE)range: < 2.4.26-0.74.19.1
- (no CPE)range: < 2.4.46-9.45.1
- (no CPE)range: < 2.4.46-9.45.1
- (no CPE)range: < 2.4.41-18.24.26.1
- (no CPE)range: < 2.4.46-9.45.1
- (no CPE)range: < 2.4.41-18.80.1
- (no CPE)range: < 2.4.41-18.24.26.1
- (no CPE)range: < 2.4.41-18.24.26.1
- (no CPE)range: < 2.4.41-18.24.26.1
- (no CPE)range: < 2.4.41-18.80.1
- (no CPE)range: < 2.4.41-18.80.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.debian.org/security/2020/dsa-4792mitrevendor-advisoryx_refsource_DEBIAN
- seclists.org/fulldisclosure/2021/Feb/14mitremailing-listx_refsource_FULLDISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2020/12/msg00008.htmlmitremailing-listx_refsource_MLIST
- security.netapp.com/advisory/ntap-20210716-0003/mitrex_refsource_CONFIRM
- support.apple.com/kb/HT212147mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.