CVE-2020-25710
28.05.2021, 11:15
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openldap | openldap | 𝑥 < 2.4.56 |
| redhat | jboss_core_services | - |
| redhat | jboss_enterprise_application_platform | 5.0.0 |
| redhat | jboss_enterprise_web_server | 2.0.0 |
| redhat | enterprise_linux | 5.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libldap-2_4-2 |
| ||||||||||||||||||||||||||||||||||||||
| libldap-2_4-2-32bit |
| ||||||||||||||||||||||||||||||||||||||
| libldap-data |
| ||||||||||||||||||||||||||||||||||||||
| openldap2 |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-back-meta |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-back-perl |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-client |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-devel |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-devel-static |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-doc |
| ||||||||||||||||||||||||||||||||||||||
| openldap2-ppolicy-check-password |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References