Debian Openldap vulnerabilities

43 known vulnerabilities affecting debian/openldap.

Total CVEs
43
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM7LOW18

Vulnerabilities

Page 1 of 3
CVE-2026-22185MEDIUMCVSS 4.62026
CVE-2026-22185 [MEDIUM] CVE-2026-22185: lmdb - OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.... OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer
debian
CVE-2023-2953HIGHCVSS 7.5fixed in openldap 2.5.16+dfsg-1 (forky)2023
CVE-2023-2953 [HIGH] CVE-2023-2953: openldap - A vulnerability was found in openldap. This security flaw causes a null pointer ... A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.5.16+dfsg-1) sid: resolved (fixed in 2.5.16+dfsg-1) trixie: resolved (fixed in 2.5.16+dfsg-1)
debian
CVE-2022-29155CRITICALCVSS 9.8fixed in openldap 2.5.12+dfsg-1 (bookworm)2022
CVE-2022-29155 [CRITICAL] CVE-2022-29155: openldap - In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerabil... In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping. Scope: local bookworm: resolved (fixed in 2.5.12+dfsg-1) bullseye
debian
CVE-2022-31253LOWCVSS 7.12022
CVE-2022-31253 [HIGH] CVE-2022-31253: openldap - A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows lo... A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1. Scope: local bookworm: resolved bullseye: resolved for
debian
CVE-2021-27212HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-2 (bookworm)2021
CVE-2021-27212 [HIGH] CVE-2021-27212: openldap - In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in... In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-2) bullseye: resolved (fixed in 2.4
debian
CVE-2020-12243HIGHCVSS 7.5fixed in openldap 2.4.50+dfsg-1 (bookworm)2020
CVE-2020-12243 [HIGH] CVE-2020-12243: openldap - In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested ... In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). Scope: local bookworm: resolved (fixed in 2.4.50+dfsg-1) bullseye: resolved (fixed in 2.4.50+dfsg-1) forky: resolved (fixed in 2.4.50+dfsg-1) sid: resolved (fixed in 2.4.50+dfsg-1) trixie: resolved (fixed in 2.4.50+dfsg
debian
CVE-2020-36222HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36222 [HIGH] CVE-2020-36222: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure ... A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.4.57+
debian
CVE-2020-25709HIGHCVSS 7.5fixed in openldap 2.4.56+dfsg-1 (bookworm)2020
CVE-2020-25709 [HIGH] CVE-2020-25709: openldap - A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malici... A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.4.56+dfsg-1) bullseye: resolved (fixed in 2.4.56+dfsg-1) forky: resolved (fixed in 2.
debian
CVE-2020-36227HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36227 [HIGH] CVE-2020-36227: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in s... A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.
debian
CVE-2020-25710HIGHCVSS 7.5fixed in openldap 2.4.56+dfsg-1 (bookworm)2020
CVE-2020-25710 [HIGH] CVE-2020-25710: openldap - A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an atta... A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.4.56+dfsg-1) bullseye: resolved (fixed in 2.4.56+dfsg-1) forky: reso
debian
CVE-2020-36229HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36229 [HIGH] CVE-2020-36229: openldap - A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a s... A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixe
debian
CVE-2020-36224HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36224 [HIGH] CVE-2020-36224: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer fr... A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed
debian
CVE-2020-36228HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36228 [HIGH] CVE-2020-36228: openldap - An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd... An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolve
debian
CVE-2020-36223HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36223 [HIGH] CVE-2020-36223: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the ... A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read). Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1
debian
CVE-2020-36225HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36225 [HIGH] CVE-2020-36225: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and sla... A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved (fixed in 2.4.57+
debian
CVE-2020-25692HIGHCVSS 7.5fixed in openldap 2.4.55+dfsg-1 (bookworm)2020
CVE-2020-25692 [HIGH] CVE-2020-25692: openldap - A NULL pointer dereference was found in OpenLDAP server and was fixed in openlda... A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service. Scope: local bookworm: resolved (fixed in 2.4.55+dfsg-1) bullseye: resolved (fixed in 2.4.55+dfsg-1) fork
debian
CVE-2020-36221HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36221 [HIGH] CVE-2020-36221: openldap - An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd c... An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck). Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (f
debian
CVE-2020-36226HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36226 [HIGH] CVE-2020-36226: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len misca... A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: resolved
debian
CVE-2020-36230HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36230 [HIGH] CVE-2020-36230: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure ... A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. Scope: local bookworm: resolved (fixed in 2.4.57+dfsg-1) bullseye: resolved (fixed in 2.4.57+dfsg-1) forky: resolved (fixed in 2.4.57+dfsg-1) sid: resolved (fixed in 2.4.57+dfsg-1) trixie: res
debian
CVE-2020-15719LOWCVSS 4.22020
CVE-2020-15719 [MEDIUM] CVE-2020-15719: openldap - libldap in certain third-party OpenLDAP packages has a certificate-validation fl... libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux. Scope: local bookworm: open bullseye: open forky: open sid: open tri
debian
Debian Openldap vulnerabilities | cvebase