CVE-2020-12243
Published: 28 April 2020
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
Priority
CVSS 3 base score: 7.5
Status
Package | Release | Status |
---|---|---|
openldap Launchpad, Ubuntu, Debian |
bionic |
Released
(2.4.45+dfsg-1ubuntu1.5)
|
eoan |
Released
(2.4.48+dfsg-1ubuntu1.1)
|
|
focal |
Released
(2.4.49+dfsg-2ubuntu1.2)
|
|
precise |
Released
(2.4.28-1.1ubuntu4.10)
|
|
trusty |
Released
(2.4.31-1+nmu2ubuntu8.5+esm2)
|
|
upstream |
Released
(2.4.50)
|
|
xenial |
Released
(2.4.42+dfsg-2ubuntu3.8)
|
|
Patches: upstream: https://git.openldap.org/openldap/openldap/-/commit/d38d48fc8f572dedfb67b9da61a2ba3b125ced91 upstream: https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440 (2.4) |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12243
- https://lists.openldap.org/hyperkitty/list/openldap-announce@openldap.org/thread/FUOYA6YCHBXMLANBJMSO22JD2NB22WGC/
- https://ubuntu.com/security/notices/USN-4352-1
- https://ubuntu.com/security/notices/USN-4352-2
- NVD
- Launchpad
- Debian