VYPR

rpm package

suse/openldap2&distro=SUSE Linux Enterprise Module for Basesystem 15 SP2

pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2

Vulnerabilities (17)

  • CVE-2020-25710HigMay 28, 2021
    affected < 2.4.46-9.45.1fixed 2.4.46-9.45.1

    A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

  • CVE-2020-25709HigMay 18, 2021
    affected < 2.4.46-9.45.1fixed 2.4.46-9.45.1

    A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

  • CVE-2021-27212HigFeb 14, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.

  • CVE-2020-8027HigFeb 11, 2021
    affected < 2.4.46-9.37.1fixed 2.4.46-9.37.1

    A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This is

  • CVE-2020-36230HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

  • CVE-2020-36229HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

  • CVE-2020-36228HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

  • CVE-2020-36227HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

  • CVE-2020-36226HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

  • CVE-2020-36225HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

  • CVE-2020-36224HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

  • CVE-2020-36223HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).

  • CVE-2020-36222HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

  • CVE-2020-36221HigJan 26, 2021
    affected < 2.4.46-9.48.1fixed 2.4.46-9.48.1

    An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

  • CVE-2020-25692HigDec 8, 2020
    affected < 2.4.46-9.40.1fixed 2.4.46-9.40.1

    A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

  • CVE-2020-8023HigSep 1, 2020
    affected < 2.4.46-9.31.1fixed 2.4.46-9.31.1

    A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterpri

  • CVE-2020-15719MedJul 14, 2020
    affected < 2.4.46-9.34.1fixed 2.4.46-9.34.1

    libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat E