CVE-2023-2953
published 2023-05-30CVE-2023-2953: A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.95%
77.9th percentile
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | >= 11.0 < 11.7.9 | 11.7.9 |
| apple | macos | >= 12.0 < 12.6.8 | 12.6.8 |
| apple | macos | >= 13.0 < 13.5 | 13.5 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
| debian | openldap | < openldap 2.5.16+dfsg-1 (forky) | openldap 2.5.16+dfsg-1 (forky) |
| msrc | cbl2_openldap_2.4.57-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | >= 0 < 2.5.16+dfsg-1 | 2.5.16+dfsg-1 |
| openldap | openldap | >= 0 < 2.5.16+dfsg-1 | 2.5.16+dfsg-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: NULL Pointer Dereference, Improper Validation of Integrity Check Value, Improper Restriction of XML External Entity Reference, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a Denial-of-Servi
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (OpenLDAP) — CVE-2023-2953
vendor_oracle·2024-10-15·CVSS 7.1
CVE-2023-2953 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (OpenLDAP) — CVE-2023-2953
Oracle Oracle Communications Risk Matrix: Configuration (OpenLDAP) vulnerability
CVE: CVE-2023-2953
CVSS: 7.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
OpenLDAP vulnerability
vendor_ubuntu·2024-01-30
CVE-2023-2953 OpenLDAP vulnerability
Title: OpenLDAP vulnerability
Summary: OpenLDAP could be made to crash if it received specially crafted input.
It was discovered that OpenLDAP was not properly performing bounds checks
when executing functions related to LDAP URLs. An attacker could possibly
use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2023-2953: macOS Ventura 13.5
vendor_apple·2023-07-24·CVSS 7.5
CVE-2023-2953 [HIGH] CVE-2023-2953: macOS Ventura 13.5
Apple Security Update: About the security content of macOS Ventura 13.5
Product: macOS Ventura
Version: 13.5
CVE: CVE-2023-2953
Component: OpenLDAP
Impact: A remote user may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-2953: macOS Monterey 12.6.8
vendor_apple·2023-07-24·CVSS 7.5
CVE-2023-2953 [HIGH] CVE-2023-2953: macOS Monterey 12.6.8
Apple Security Update: About the security content of macOS Monterey 12.6.8
Product: macOS Monterey
Version: 12.6.8
CVE: CVE-2023-2953
Component: OpenLDAP
Impact: A remote user may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-2953: macOS Big Sur 11.7.9
vendor_apple·2023-07-24·CVSS 7.5
CVE-2023-2953 [HIGH] CVE-2023-2953: macOS Big Sur 11.7.9
Apple Security Update: About the security content of macOS Big Sur 11.7.9
Product: macOS Big Sur
Version: 11.7.9
CVE: CVE-2023-2953
Component: OpenLDAP
Impact: A remote user may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
Ubuntu
OpenLDAP vulnerability
vendor_ubuntu·2023-07-03
CVE-2023-2953 OpenLDAP vulnerability
Title: OpenLDAP vulnerability
Summary: OpenLDAP could be made to crash if it received specially crafted
input.
It was discovered that OpenLDAP was not properly performing bounds checks
when executing functions related to LDAP URLs. An attacker could possibly
use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openldap: null pointer dereference in ber_memalloc_x function
vendor_redhat·2023-05-29·CVSS 7.5
CVE-2023-2953 [HIGH] CWE-476 openldap: null pointer dereference in ber_memalloc_x function
openldap: null pointer dereference in ber_memalloc_x function
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
A vulnerability was found in OpenLDAP, in ber_memalloc_x() function, leading to a null pointer dereference. This flaw can result in reduced system memory and cause LDAP authentication failures. The impact is primarily a disruption in authentication processes, which may hinder user access or service operations relying on LDAP for authentication.
Statement: This vulnerability is rated as a low severity because, it affects only systems where memory exhaustion might occur due to mishandling of users crafted inputs, and it requires an authenticated user to trigger the issue.
Package: compat-openldap (Red Hat E
Microsoft
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
vendor_msrc·2023-05-09·CVSS 7.5
CVE-2023-2953 [HIGH] CWE-476 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Requir
Debian
CVE-2023-2953: openldap - A vulnerability was found in openldap. This security flaw causes a null pointer ...
vendor_debian·2023·CVSS 7.5
CVE-2023-2953 [HIGH] CVE-2023-2953: openldap - A vulnerability was found in openldap. This security flaw causes a null pointer ...
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.5.16+dfsg-1)
sid: resolved (fixed in 2.5.16+dfsg-1)
trixie: resolved (fixed in 2.5.16+dfsg-1)
GHSA
GHSA-26fx-c7cw-5jh4: A vulnerability was found in openldap
ghsa_unreviewed·2023-05-31
CVE-2023-2953 [HIGH] CWE-476 GHSA-26fx-c7cw-5jh4: A vulnerability was found in openldap
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
OSV
CVE-2023-2953: A vulnerability was found in openldap
osv·2023-05-30·CVSS 7.5
CVE-2023-2953 [HIGH] CVE-2023-2953: A vulnerability was found in openldap
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2023/Jul/47http://seclists.org/fulldisclosure/2023/Jul/48http://seclists.org/fulldisclosure/2023/Jul/52https://access.redhat.com/security/cve/CVE-2023-2953https://bugs.openldap.org/show_bug.cgi?id=9904https://security.netapp.com/advisory/ntap-20230703-0005/https://support.apple.com/kb/HT213843https://support.apple.com/kb/HT213844https://support.apple.com/kb/HT213845http://seclists.org/fulldisclosure/2023/Jul/47http://seclists.org/fulldisclosure/2023/Jul/48http://seclists.org/fulldisclosure/2023/Jul/52https://access.redhat.com/security/cve/CVE-2023-2953https://bugs.openldap.org/show_bug.cgi?id=9904https://security.netapp.com/advisory/ntap-20230703-0005/https://support.apple.com/kb/HT213843https://support.apple.com/kb/HT213844https://support.apple.com/kb/HT213845
2023-05-30
Published