7.5
CVSSv3

CVE-2020-25692

Published: 08/12/2020 Updated: 12/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A NULL pointer dereference flaw was found in the OpenLDAP server, during a request for renaming RDNs. This flaw allows a remote, unauthenticated malicious user to crash the slapd process by sending a specially crafted request, causing a denial of service. The highest threat from this vulnerability is to system availability. (CVE-2020-25692)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux 5.0

netapp cloud backup -

netapp solidfire_baseboard_management_controller_firmware -

Vendor Advisories

A vulnerability in the handling of normalization with modrdn was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a specially crafted packet For the stable distribution (buster), this problem has bee ...
A NULL pointer dereference flaw was found in the OpenLDAP server, during a request for renaming RDNs This flaw allows a remote, unauthenticated attacker to crash the slapd process by sending a specially crafted request, causing a denial of service The highest threat from this vulnerability is to system availability (CVE-2020-25692) ...