Vulnerability CVE-2020-36227: Information

Description

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Jan. 26, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-835

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
openldapsisyphus2.4.57-alt12.6.7-alt1ALT-PU-2021-1333-1266287Fixed
openldapp102.4.57-alt12.4.59-alt1.p10.2ALT-PU-2021-1333-1266287Fixed
openldapp92.4.57-alt0.M90P.12.4.59-alt0.p9.1ALT-PU-2021-1352-1266288Fixed
openldapc10f12.4.57-alt12.4.59-alt1.p10.2ALT-PU-2021-1333-1266287Fixed
openldapc9f22.4.57-alt0.M90P.12.4.59-alt0.c9.2ALT-PU-2021-1354-1266289Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*
      End excliding
      2.4.57

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
      Start including
      11.1
      End excliding
      11.4