Reachable Assertion in OpenLDAP - CVE-2020-25710
Published: November 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when processing LDAP requests in slapd within the csnNormalize23() function in schema_init.c. A remote attacker can send a specially crafted packet to the server, trigger an assertion failure and crash the daemon.
Affected software
Red Hat OpenShift GitOps
IBM QRadar Network Security
openldap (Debian package)
openldap (Alpine package)
openldap (Red Hat package)
slapd (Ubuntu package)
openldap-servers-sql
openldap-servers
openldap-devel
openldap-clients
openldap
openldap-help
openldap-debugsource
openldap-debuginfo
Red Hat Enterprise Linux Workstation
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
CentOS
Red Hat Enterprise Linux Server
Ubuntu
openEuler
IBM Security Access Manager for Enterprise Single-Sign On
Session Smart Router
SDM600
Migration Toolkit for Containers
XtremIO X2
Juniper Junos Space
How to mitigate CVE-2020-25710
Red Hat OpenShift GitOps - addressed in versions 1.2.3, 1.3.6
openldap (Debian package) - update to 2.4.47+dfsg-3+deb10u4
openldap (Red Hat package) - update to 2.4.44-25.el7_9
IBM QRadar Network Security - addressed in versions 5.4.0.16, 5.5.0.11
SDM600 - update to 1.2 FP2 HF10
Migration Toolkit for Containers - update to 1.5.4
slapd (Ubuntu package) - addressed in versions 2.4.28-1.1ubuntu4.12, 2.4.31-1+nmu2ubuntu8.5+esm4, 2.4.42+dfsg-2ubuntu3.11, 2.4.45+dfsg-1ubuntu1.8, 2.4.49+dfsg-2ubuntu1.5, 2.4.53+dfsg-1ubuntu1.2
openldap-servers-sql - update to 2.4.44-25
openldap-servers - update to 2.4.44-25
openldap-devel - update to 2.4.44-25
openldap-clients - update to 2.4.44-25
openldap - update to 2.4.44-25
openldap-clients - update to 2.4.50-6
openldap - update to 2.4.50-6
openldap-devel - update to 2.4.50-6
openldap-servers - update to 2.4.50-6
openldap-help - update to 2.4.50-6
openldap-debugsource - update to 2.4.50-6
openldap-debuginfo - update to 2.4.50-6
Session Smart Router - addressed in versions 5.4.7, 5.5.3
XtremIO X2 - update to 6.4.2-13
Juniper Junos Space - update to 22.2R1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenLDAP
- Debian update for openldap
- Reachable Assertion in openldap (Alpine package)
- Red Hat Enterprise Linux 7 update for openldap
- CentOS 7 update for openldap
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.2
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.3
- Multiple vulnerabilities in Hitachi Energy SDM600
- Multiple vulnerabilities in IBM QRadar Network Security
- Multiple vulnerabilities in IBM Security Access Manager
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- openEuler 20.03 LTS SP1 update for openldap
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Multiple vulnerabilities in Dell XtremIO X2
- Anolis OS update for openldap
- Ubuntu update for openldap
- Ubuntu update for openldap