Vulnerabilities
Vulnerable Software
Openldap:  >> Openldap  >> 2.4.56  Security Vulnerabilities
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
CVSS Score
9.8
EPSS Score
0.699
Published
2022-05-04
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
CVSS Score
7.5
EPSS Score
0.641
Published
2021-02-14
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.043
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.043
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.777
Published
2021-01-26
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.834
Published
2021-01-26
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.043
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.123
Published
2021-01-26
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
CVSS Score
7.5
EPSS Score
0.842
Published
2021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
CVSS Score
7.5
EPSS Score
0.777
Published
2021-01-26


Contact Us

Shodan ® - All rights reserved