Related Vulnerabilities: CVE-2020-36226  

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

Severity Medium

Remote Yes

Type Denial of service

Description

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

AVG-1489 openldap 2.4.56-1 2.4.57-1 Medium Testing

https://bugs.openldap.org/show_bug.cgi?id=9413
https://git.openldap.org/openldap/openldap/-/commit/d169e7958a3e0dc70f59c8374bf8a59833b7bdd8