Back to Database
Status published
High
CVE-2020-36229
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57...
Vulnerability Description
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36229
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
- https://bugs.openldap.org/show_bug.cgi?id=9425
- https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0
- https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html
- https://www.debian.org/security/2021/dsa-4845
- https://security.netapp.com/advisory/ntap-20210226-0002/
- https://support.apple.com/kb/HT212529
- https://support.apple.com/kb/HT212531
- https://support.apple.com/kb/HT212530
- http://seclists.org/fulldisclosure/2021/May/70
- http://seclists.org/fulldisclosure/2021/May/64
- http://seclists.org/fulldisclosure/2021/May/65
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
More from openldap
View All →CVE-2022-29155
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a...
Critical
9.8
CVE-2021-27212
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion...
High
7.5
CVE-2020-36230
A flaw was discovered in OpenLDAP before 2.4.57 leading in...
High
7.5
CVE-2020-36228
An integer underflow was discovered in OpenLDAP before 2.4.57 leading...
High
7.5
CVE-2020-36227
A flaw was discovered in OpenLDAP before 2.4.57 leading to...
High
7.5
Affected Vendor
openldap
View all reports →Affected Software
openldap, debian linux, mac os x, macos
Vulnerable Versions:
0, 9.0, 10.0, 10.14.0, 10.14.6, 11.1
Timeline
Official Publish:
January 25th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.