Vulnerabilities
Vulnerable Software
Openldap:  >> Openldap  >> 2.4.56  Security Vulnerabilities
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
CVSS Score
9.8
EPSS Score
0.203
Published
2022-05-04
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
CVSS Score
7.5
EPSS Score
0.251
Published
2021-02-14
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.008
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.006
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.687
Published
2021-01-26
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.735
Published
2021-01-26
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.02
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.013
Published
2021-01-26
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
CVSS Score
7.5
EPSS Score
0.575
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.393
Published
2021-01-26


Contact Us

Shodan ® - All rights reserved