cbcvebase.
CVE-2023-2953
published 2023-05-30

CVE-2023-2953: A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Affected

16 ranges
VendorProductVersion rangeFixed in
applemacos>= 11.0 < 11.7.911.7.9
applemacos>= 12.0 < 12.6.812.6.8
applemacos>= 13.0 < 13.513.5
applemacos_big_sur
applemacos_monterey
applemacos_ventura
debianopenldap< openldap 2.5.16+dfsg-1 (forky)openldap 2.5.16+dfsg-1 (forky)
msrccbl2_openldap_2.4.57-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
openldapopenldap
openldapopenldap
openldapopenldap>= 0 < 2.5.16+dfsg-12.5.16+dfsg-1
openldapopenldap>= 0 < 2.5.16+dfsg-12.5.16+dfsg-1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH