Your submission was sent successfully! Close

CVE-2020-25692

Published: 30 October 2020

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
openldap
Launchpad, Ubuntu, Debian
bionic
Released (2.4.45+dfsg-1ubuntu1.7)
focal
Released (2.4.49+dfsg-2ubuntu1.4)
groovy
Released (2.4.53+dfsg-1ubuntu1.1)
precise
Released (2.4.28-1.1ubuntu4.11)
trusty
Released (2.4.31-1+nmu2ubuntu8.5+esm3)
upstream
Released (2.4.55+dfsg-1)
xenial
Released (2.4.42+dfsg-2ubuntu3.10)
Patches:
upstream: https://git.openldap.org/openldap/openldap/-/commit/4c774220a752bf8e3284984890dc0931fe73165d