Debian Openldap vulnerabilities
34 known vulnerabilities affecting debian/openldap.
Total CVEs
34
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM6LOW10
Vulnerabilities
Page 2 of 2
CVE-2020-36226P3HIGHCVSS 7.5fixed in openldap 2.4.57+dfsg-1 (bookworm)2020
CVE-2020-36226 [HIGH] CVE-2020-36226: openldap - A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len misca...
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
Scope: local
bookworm: resolved (fixed in 2.4.57+dfsg-1)
bullseye: resolved (fixed in 2.4.57+dfsg-1)
forky: resolved (fixed in 2.4.57+dfsg-1)
sid: resolved (fixed in 2.4.57+dfsg-1)
trixie: resolved
debian
CVE-2023-2953P3HIGHCVSS 7.5fixed in openldap 2.5.16+dfsg-1 (forky)2023
CVE-2023-2953 [HIGH] CVE-2023-2953: openldap - A vulnerability was found in openldap. This security flaw causes a null pointer ...
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.5.16+dfsg-1)
sid: resolved (fixed in 2.5.16+dfsg-1)
trixie: resolved (fixed in 2.5.16+dfsg-1)
debian
CVE-2020-12243P3HIGHCVSS 7.5fixed in openldap 2.4.50+dfsg-1 (bookworm)2020
CVE-2020-12243 [HIGH] CVE-2020-12243: openldap - In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested ...
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
Scope: local
bookworm: resolved (fixed in 2.4.50+dfsg-1)
bullseye: resolved (fixed in 2.4.50+dfsg-1)
forky: resolved (fixed in 2.4.50+dfsg-1)
sid: resolved (fixed in 2.4.50+dfsg-1)
trixie: resolved (fixed in 2.4.50+dfsg
debian
CVE-2017-9287P3MEDIUMCVSS 6.5fixed in openldap 2.4.44+dfsg-5 (bookworm)2017
CVE-2017-9287 [MEDIUM] CVE-2017-9287: openldap - servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double ...
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
Scope: local
bookworm: resolved (fixed in 2.4.44+dfsg-5)
bullseye: resolved (fixed in 2.4.44+dfsg-5)
forky: resolved (fixed in 2.
debian
CVE-2019-13057P4LOWCVSS 4.9fixed in openldap 2.4.48+dfsg-1 (bookworm)2019
CVE-2019-13057 [MEDIUM] CVE-2019-13057: openldap - An issue was discovered in the server in OpenLDAP before 2.4.48. When the server...
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a
debian
CVE-2011-1024P4LOWCVSS 4.6fixed in openldap 2.4.25-1 (bookworm)2011
CVE-2011-1024 [MEDIUM] CVE-2011-1024: openldap - chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave config...
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
Scope: local
bookworm: resolved (fixed in 2.4.25-1)
bul
debian
CVE-2015-1545P4MEDIUMCVSS 5.0fixed in openldap 2.4.40-4 (bookworm)2015
CVE-2015-1545 [MEDIUM] CVE-2015-1545: openldap - The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.1...
The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
Scope: local
bookworm: resolved (fixed in 2.4.40-4)
bullseye: resolved (fixed in 2.4.40-4)
forky: resolved (fixe
debian
CVE-2010-0212P4MEDIUMCVSS 5.0fixed in openldap 2.4.23-1 (bookworm)2010
CVE-2010-0212 [MEDIUM] CVE-2010-0212: openldap - OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via...
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.
Scope: local
bookwo
debian
CVE-2013-4449P4LOWCVSS 4.3fixed in openldap 2.4.39-1.1 (bookworm)2013
CVE-2013-4449 [MEDIUM] CVE-2013-4449: openldap - The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count ...
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.
Scope: local
bookworm: resolved (fixed in 2.4.39-1.1
debian
CVE-2009-3767P4LOWCVSS 5.9fixed in openldap 2.4.17-2.1 (bookworm)2009
CVE-2009-3767 [MEDIUM] CVE-2009-3767: openldap - libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, ...
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Author
debian
CVE-2015-1546P4MEDIUMCVSS 5.0fixed in openldap 2.4.40-4 (bookworm)2015
CVE-2015-1546 [MEDIUM] CVE-2015-1546: openldap - Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c...
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
Scope: local
bookworm: resolved (fixed in 2.4.40-4)
bullseye: resolved (fixed in 2.4.40-4)
forky: resolved (fixed in 2.4.40-4)
sid: resolved (fixed
debian
CVE-2014-9713P4MEDIUMCVSS 4.0fixed in openldap 2.4.40-2 (bookworm)2014
CVE-2014-9713 [MEDIUM] CVE-2014-9713: openldap - The default slapd configuration in the Debian openldap package 2.4.23-3 through ...
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.4.40-2)
bullseye: resolved (fixed in 2.4.40-2)
forky: resolved (fixed in 2.4.40-2)
sid: resolved (fixed in 2.4.40-
debian
CVE-2011-4079P4LOWCVSS 4.0fixed in openldap 2.4.28-1 (bookworm)2011
CVE-2011-4079 [MEDIUM] CVE-2011-4079: openldap - Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earl...
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.
Scope: local
bookworm: resolved (fixed in 2.4.28-1)
bullseye: resolve
debian
CVE-2012-1164P4LOWCVSS 2.6fixed in openldap 2.4.31-1 (bookworm)2012
CVE-2012-1164 [LOW] CVE-2012-1164: openldap - slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of ser...
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
Scope: local
bookworm: resolved (fixed in 2.4.31-1)
bullseye: resolved (fixed in 2.4.31-1)
forky: resolved (fixed in 2.4.31-1)
sid: resolved (fixed in
debian
← Previous2 / 2