7.5
CVSSv3

CVE-2021-20277

Published: 12/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #985935 ldb: CVE-2021-20277 Package: src:ldb; Maintainer for src:ldb is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 26 Mar 2021 11:51:01 UTC Severity: grave Tags: patch, pending, security, upstream Found ...
Multiple vulnerabilities have been discovered in ldb, a LDAP-like embedded database built on top of TDB CVE-2020-10730 Andrew Bartlett discovered a NULL pointer dereference and use-after-free flaw when handling ASQ and VLV LDAP controls and combinations with the LDAP paged_results feature CVE-2020-27840 Douglas Bagnall discovered ...
A flaw was found in Samba's libldb Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request The highest threat from this vulnerability is to system availability (CVE-2021-20277) ...
A flaw was found in Samba's libldb Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request The highest threat from this vulnerability is to system availability (CVE-2021-20277) ...
A flaw was found in samba Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write The highest threat from this vulnerability is to system availability ...
A security issue has been found in Samba before version 4142 A string in an LDAP attribute that contains multiple consecutive leading spaces can lead to a memmove() of out of bounds memory in ldb_handler_fold() ldb_handler_fold() is used by case insensitive strings - that is most string attributes - in Active Directory As the search expression ...