Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2023-2953

Published: 30 May 2023

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Priority

Low

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
openldap
Launchpad, Ubuntu, Debian
bionic
Released (2.4.45+dfsg-1ubuntu1.11+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
focal
Released (2.4.49+dfsg-2ubuntu1.10)
jammy
Released (2.5.16+dfsg-0ubuntu0.22.04.2)
kinetic Ignored
(end of life, was needed)
lunar Ignored
(end of life, was needed)
mantic Not vulnerable
(2.6.4+dfsg-1~exp1ubuntu1)
trusty
Released (2.4.31-1+nmu2ubuntu8.5+esm6)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (2.6.4)
xenial
Released (2.4.42+dfsg-2ubuntu3.13+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
Patches:
upstream: https://git.openldap.org/openldap/openldap/-/commit/ea8dd2d279c5aeaf9d4672a4e95bebd99babcce1
upstream: https://git.openldap.org/openldap/openldap/-/commit/3f2abd0b2eeec8522e50d5c4ea4992e70e8f9915
upstream: https://git.openldap.org/openldap/openldap/-/commit/c5c8c06a8bd52ea7b843e7d8ca961a7d1800ce5f
upstream: https://git.openldap.org/openldap/openldap/-/commit/840944e26f734bb03d925f26c4ef11a6cedcbb9c
upstream: https://git.openldap.org/openldap/openldap/-/commit/752d320cf96e46f24c0900f1a8f6af0a3fc3c4ce
upstream: https://git.openldap.org/openldap/openldap/-/commit/6563fab9e2feccb0a684d0398e78571d09fb808b

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H