5
CVSSv2

CVE-2020-36222

Published: 26/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw exists in OpenLDAP prior to 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap

debian debian linux 9.0

debian debian linux 10.0

apple mac os x

apple mac os x 10.14.6

apple macos

Vendor Advisories

Several vulnerabilities were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service (slapd daemon crash, infinite loops) via specially crafted packets For the stable distribution (buster), these problems have been ...
An issue was discovered in OpenLDAP 2x before 2448 When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs After the first SASL bind is completed, the sasl_ssf ...
An issue was discovered in OpenLDAP 2x before 2448 When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs After the first SASL bind is completed, the sasl_ssf ...
A flaw was discovered in OpenLDAP before 2457 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2021-05-25-3 Security Update 2021-004 Mojave <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: App ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2021-05-25-4 Security Update 2021-003 Catalina <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: A ...