Resource management error in OpenLDAP - CVE-2020-12243
Published: April 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error when performing searches with nested boolean expressions in filter.c within the slapd daemon in OpenLDAP. A remote attacker can send a specially crafted LDAP request to the affected server and crash the LDAP service.
Affected software
Ansible Automation Platform
openldap (Alpine package)
openldap (Ubuntu package)
openldap (Debian package)
openldap (Red Hat package)
openldap-debugsource
openldap-servers
openldap-devel
openldap-debuginfo
openldap-clients
openldap-help
openldap
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Opensuse
openEuler
Splunk Enterprise
SDM600
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-12243
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
openldap (Alpine package) - addressed in versions 2.4.48-r1, 2.4.48-r2
openldap (Ubuntu package) - addressed in versions 2.4.42+dfsg-2ubuntu3.8, 2.4.45+dfsg-1ubuntu1.5, 2.4.48+dfsg-1ubuntu1.1, 2.4.49+dfsg-2ubuntu1.2
openldap (Debian package) - addressed in versions 2.4.44+dfsg-5+deb9u4, 2.4.47+dfsg-3+deb10u2
openldap (Red Hat package) - update to 2.4.44-22.el7
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
SDM600 - update to 1.2 FP2 HF10
openldap-debugsource - update to 2.4.49-2
openldap-servers - update to 2.4.49-2
openldap-devel - update to 2.4.49-2
openldap-debuginfo - update to 2.4.49-2
openldap-clients - update to 2.4.49-2
openldap-help - update to 2.4.49-2
openldap - update to 2.4.49-2
Red Hat OpenShift Container Platform - update to 4.3.40
External References
Related Security Bulletins
- Denial of service in OpenLDAP
- Debian update for openldap
- Ubuntu update for OpenLDAP
- OpenSUSE Linux update for openldap2
- Resource management error in openldap (Alpine package)
- Red Hat Enterprise Linux 7 update for openldap
- Multiple vulnerabilities in Hitachi Energy SDM600
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- openEuler 20.03 LTS update for openldap-2.4.49-2
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3