Vulnerability CVE-2023-2953: Information
Description
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| openldap | p10 | 2.4.59-alt1.p10.3 | 2.4.59-alt1.p10.3 | ALT-PU-2025-2746-3 | 374530 | Fixed |
| openldap | p10_e2k | 2.4.59-alt1.p10.3 | 2.4.59-alt1.p10.3 | ALT-PU-2025-4262-1 | - | Fixed |
| openldap | c10f2 | 2.4.59-alt1.p10.3 | 2.4.59-alt1.p10.4 | ALT-PU-2025-3390-2 | 375846 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
|---|---|
| http://seclists.org/fulldisclosure/2023/Jul/47 |
|
| http://seclists.org/fulldisclosure/2023/Jul/48 |
|
| http://seclists.org/fulldisclosure/2023/Jul/52 |
|
| https://access.redhat.com/security/cve/CVE-2023-2953 |
|
| https://bugs.openldap.org/show_bug.cgi?id=9904 |
|
| https://security.netapp.com/advisory/ntap-20230703-0005/ |
|
| https://support.apple.com/kb/HT213843 |
|
| https://support.apple.com/kb/HT213844 |
|
| https://support.apple.com/kb/HT213845 |
|
| BDU:2023-04057 |