CVE-2023-2953

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
openldapopenldap
2.4
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
applemacos
11.0 ≤
𝑥
< 11.7.9
applemacos
12.0 ≤
𝑥
< 12.6.8
applemacos
13.0 ≤
𝑥
< 13.5
netappactive_iq_unified_manager
-
netappclustered_data_ontap
-
netappontap_tools
-
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openldap
bullseye (security)
vulnerable
bullseye
no-dsa
bookworm
no-dsa
buster
no-dsa
sid
2.5.19+dfsg-1
fixed
trixie
2.5.19+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openldap
noble
not-affected
mantic
not-affected
lunar
ignored
kinetic
ignored
jammy
Fixed 2.5.16+dfsg-0ubuntu0.22.04.2
released
focal
Fixed 2.4.49+dfsg-2ubuntu1.10
released
bionic
Fixed 2.4.45+dfsg-1ubuntu1.11+esm1
released
xenial
Fixed 2.4.42+dfsg-2ubuntu3.13+esm2
released
trusty
Fixed 2.4.31-1+nmu2ubuntu8.5+esm6
released