Resource management error in OpenLDAP - CVE-2020-12243

 

Resource management error in OpenLDAP - CVE-2020-12243

Published: April 29, 2020


Vulnerability identifier: #VU27445
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12243
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error when performing searches with nested boolean expressions in filter.c within the slapd daemon in OpenLDAP. A remote attacker can send a specially crafted LDAP request to the affected server and crash the LDAP service.


Affected software

OpenLDAP
Ansible Automation Platform
openldap (Alpine package)
openldap (Ubuntu package)
openldap (Debian package)
openldap (Red Hat package)
openldap-debugsource
openldap-servers
openldap-devel
openldap-debuginfo
openldap-clients
openldap-help
openldap
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Opensuse
openEuler
Splunk Enterprise
SDM600
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-12243

Install updates from vendor's website.

OpenLDAP - update to 2.4.50
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
openldap (Alpine package) - addressed in versions 2.4.48-r1, 2.4.48-r2
openldap (Ubuntu package) - addressed in versions 2.4.42+dfsg-2ubuntu3.8, 2.4.45+dfsg-1ubuntu1.5, 2.4.48+dfsg-1ubuntu1.1, 2.4.49+dfsg-2ubuntu1.2
openldap (Debian package) - addressed in versions 2.4.44+dfsg-5+deb9u4, 2.4.47+dfsg-3+deb10u2
openldap (Red Hat package) - update to 2.4.44-22.el7
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
SDM600 - update to 1.2 FP2 HF10
openldap-debugsource - update to 2.4.49-2
openldap-servers - update to 2.4.49-2
openldap-devel - update to 2.4.49-2
openldap-debuginfo - update to 2.4.49-2
openldap-clients - update to 2.4.49-2
openldap-help - update to 2.4.49-2
openldap - update to 2.4.49-2
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins