cbcvebase.

Debian Openldap vulnerabilities

34 known vulnerabilities affecting debian/openldap.

Total CVEs
34
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM6LOW10

Vulnerabilities

Page 1 of 2
CVE-2010-0211P2CRITICALCVSS 9.8PoCfixed in openldap 2.4.23-1 (bookworm)2010
CVE-2010-0211 [CRITICAL] CVE-2010-0211: openldap - The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the ... The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, unini
debian
CVE-2022-29155P2CRITICALCVSS 9.8fixed in openldap 2.5.12+dfsg-1 (bookworm)2022
CVE-2022-29155 [CRITICAL] CVE-2022-29155: openldap - In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerabil... In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping. Scope: local bookworm: resolved (fixed in 2.5.12+dfsg-1) bullseye
debian
CVE-2020-36221P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36221 [HIGH] CVE-2020-36221: openldap - An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd c... An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck). Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (f
debian
CVE-2020-36228P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36228 [HIGH] CVE-2020-36228: openldap - An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd... An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolve
debian
CVE-2020-36222P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36222 [HIGH] CVE-2020-36222: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure ... A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.4.57+
debian
CVE-2020-36227P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36227 [HIGH] CVE-2020-36227: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in s... A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.
debian
CVE-2021-27212P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-2 (bookworm)2021
CVE-2021-27212 [HIGH] CVE-2021-27212: openldap - In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in... In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-2) bullseye: resolved (fixed in 2.4
debian
CVE-2015-6908P3MEDIUMCVSS 5.0PoCfixed in openldap 2.4.42+dfsg-2 (bookworm)2015
CVE-2015-6908 [MEDIUM] CVE-2015-6908: openldap - The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earli... The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. Scope: local bookworm: resolved (fixed in 2.4.42+dfsg-2) bullseye: resolved (fixed in 2.4.42+dfsg-2) forky: resolved (fix
debian
CVE-2011-1081P4LOWCVSS 5.0PoCfixed in openldap 2.4.25-1 (bookworm)2011
CVE-2011-1081 [MEDIUM] CVE-2011-1081: openldap - modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cau... modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field. Scope: local bookworm: resolved (fixed in 2.4.25-1) bullseye: resolved (fixed in 2.4.25-1) forky: resolved (fixed in
debian
CVE-2008-2952P4LOWCVSS 5.0PoCfixed in openldap 2.4.10-3 (bookworm)2008
CVE-2008-2952 [MEDIUM] CVE-2008-2952: openldap - liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a deni... liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error. Scope: local bookworm: resolved (fixed in 2.4.10-3) bullseye: resolved (fixed in 2.4.10-3) forky: resolved (fixed in 2.4.10-3) sid: resolved (fixed in 2.4.10-3) trixie: resolved (fixed i
debian
CVE-2019-13565P3LOWCVSS 7.5fixed in openldap 2.4.48+dfsg-1 (bookworm)2019
CVE-2019-13565 [HIGH] CVE-2019-13565: openldap - An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentic... An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained
debian
CVE-2011-1025P3LOWCVSS 6.8fixed in openldap 2.4.25-1 (bookworm)2011
CVE-2011-1025 [MEDIUM] CVE-2011-1025: openldap - bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentica... bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password. Scope: local bookworm: resolved (fixed in 2.4.25-1) bullseye: resolved (fixed in 2.4.25-1) forky: resolved (fixed in 2.4.25-1) sid: resolved (fixed
debian
CVE-2020-36230P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36230 [HIGH] CVE-2020-36230: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure ... A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: res
debian
CVE-2020-25709P3HIGHCVSS 7.5fixed in openldap 2.4.56+dfsg-1 (bookworm)2020
CVE-2020-25709 [HIGH] CVE-2020-25709: openldap - A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malici... A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.4.56+dfsg-1) bullseye: resolved (fixed in 2.4.56+dfsg-1) forky: resolved (fixed in 2.
debian
CVE-2020-25710P3HIGHCVSS 7.5fixed in openldap 2.4.56+dfsg-1 (bookworm)2020
CVE-2020-25710 [HIGH] CVE-2020-25710: openldap - A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an atta... A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.4.56+dfsg-1) bullseye: resolved (fixed in 2.4.56+dfsg-1) forky: reso
debian
CVE-2020-36225P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36225 [HIGH] CVE-2020-36225: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and sla... A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.4.57+
debian
CVE-2020-25692P3HIGHCVSS 7.5fixed in openldap 2.4.55+dfsg-1 (bookworm)2020
CVE-2020-25692 [HIGH] CVE-2020-25692: openldap - A NULL pointer dereference was found in OpenLDAP server and was fixed in openlda... A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service. Scope: local bookworm: resolved (fixed in 2.4.55+dfsg-1) bullseye: resolved (fixed in 2.4.55+dfsg-1) fork
debian
CVE-2020-36224P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36224 [HIGH] CVE-2020-36224: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer fr... A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed
debian
CVE-2020-36229P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36229 [HIGH] CVE-2020-36229: openldap - A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a s... A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixe
debian
CVE-2020-36223P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36223 [HIGH] CVE-2020-36223: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the ... A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read). Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1
debian