rpm package
suse/openldap2&distro=SUSE Linux Enterprise Module for Basesystem 15 SP2
pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
Vulnerabilities (17)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-25710 | Hig | 7.5 | < 2.4.46-9.45.1 | 2.4.46-9.45.1 | May 28, 2021 | A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. | |
| CVE-2020-25709 | Hig | 7.5 | < 2.4.46-9.45.1 | 2.4.46-9.45.1 | May 18, 2021 | A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability. | |
| CVE-2021-27212 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Feb 14, 2021 | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime. | |
| CVE-2020-8027 | Hig | 7.3 | < 2.4.46-9.37.1 | 2.4.46-9.37.1 | Feb 11, 2021 | A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This is | |
| CVE-2020-36230 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. | |
| CVE-2020-36229 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service. | |
| CVE-2020-36228 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. | |
| CVE-2020-36227 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. | |
| CVE-2020-36226 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service. | |
| CVE-2020-36225 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service. | |
| CVE-2020-36224 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service. | |
| CVE-2020-36223 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read). | |
| CVE-2020-36222 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | |
| CVE-2020-36221 | Hig | 7.5 | < 2.4.46-9.48.1 | 2.4.46-9.48.1 | Jan 26, 2021 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck). | |
| CVE-2020-25692 | Hig | 7.5 | < 2.4.46-9.40.1 | 2.4.46-9.40.1 | Dec 8, 2020 | A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service. | |
| CVE-2020-8023 | Hig | 7.7 | < 2.4.46-9.31.1 | 2.4.46-9.31.1 | Sep 1, 2020 | A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterpri | |
| CVE-2020-15719 | Med | 4.2 | < 2.4.46-9.34.1 | 2.4.46-9.34.1 | Jul 14, 2020 | libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat E |
- affected < 2.4.46-9.45.1fixed 2.4.46-9.45.1
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
- affected < 2.4.46-9.45.1fixed 2.4.46-9.45.1
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
- affected < 2.4.46-9.37.1fixed 2.4.46-9.37.1
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This is
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
- affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
- affected < 2.4.46-9.40.1fixed 2.4.46-9.40.1
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
- affected < 2.4.46-9.31.1fixed 2.4.46-9.31.1
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterpri
- affected < 2.4.46-9.34.1fixed 2.4.46-9.34.1
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat E