Type Confusion in OpenLDAP - CVE-2020-36229
Published: January 26, 2021 / Updated: February 6, 2021
Vulnerability identifier: #VU50396
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-36229
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a type confusion error in ldap_X509dn2bv when parsing X.509 DN in ad_keystring. A remote attacker can send a specially crafted request to slapd and crash it.
Affected software
OpenLDAP
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
openEuler
openldap (Debian package)
openldap2-ppolicy-check-password-debuginfo
openldap2-ppolicy-check-password
compat-libldap-2_3-0
compat-libldap-2_3-0-debuginfo
openldap2-back-meta
openldap2-client-debuginfo
libldap-openssl1-2_4-2-x86
libldap-openssl1-2_4-2-32bit
openldap2-openssl1
openldap2-client-openssl1
libldap-openssl1-2_4-2
libldap-2_4-2-32bit
openldap2-client
openldap2-debugsource
openldap2
libldap-2_4-2
openldap2-client-debugsource
openldap2-client-openssl1-debugsource
openldap2-client-openssl1-debuginfo
openldap2-debuginfo
openldap (Ubuntu package)
openldap
openldap2-back-perl
openldap2-back-perl-debuginfo
openldap2-devel
openldap2-devel-static
openldap2-back-meta-debuginfo
libldap-2_4-2-debuginfo-32bit
libldap-2_4-2-debuginfo
openldap2-doc
slapd (Ubuntu package)
libldap-data
libldap-2_4-2-32bit-debuginfo
openldap2-devel-32bit
openldap-help
openldap-devel
openldap-clients
openldap-debuginfo
openldap-debugsource
openldap-servers
Splunk Enterprise
RTU500 CMU
SDM600
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
openEuler
openldap (Debian package)
openldap2-ppolicy-check-password-debuginfo
openldap2-ppolicy-check-password
compat-libldap-2_3-0
compat-libldap-2_3-0-debuginfo
openldap2-back-meta
openldap2-client-debuginfo
libldap-openssl1-2_4-2-x86
libldap-openssl1-2_4-2-32bit
openldap2-openssl1
openldap2-client-openssl1
libldap-openssl1-2_4-2
libldap-2_4-2-32bit
openldap2-client
openldap2-debugsource
openldap2
libldap-2_4-2
openldap2-client-debugsource
openldap2-client-openssl1-debugsource
openldap2-client-openssl1-debuginfo
openldap2-debuginfo
openldap (Ubuntu package)
openldap
openldap2-back-perl
openldap2-back-perl-debuginfo
openldap2-devel
openldap2-devel-static
openldap2-back-meta-debuginfo
libldap-2_4-2-debuginfo-32bit
libldap-2_4-2-debuginfo
openldap2-doc
slapd (Ubuntu package)
libldap-data
libldap-2_4-2-32bit-debuginfo
openldap2-devel-32bit
openldap-help
openldap-devel
openldap-clients
openldap-debuginfo
openldap-debugsource
openldap-servers
Splunk Enterprise
RTU500 CMU
SDM600
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2020-36229
Install updates from vendor's website.
OpenLDAP - update to 2.4.57
openldap (Debian package) - update to 2.4.47+dfsg-3+deb10u5
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
macOS - addressed in versions 10.14.6 18G9216, 10.15.7 19H1217, 11.4 20F71
RTU500 CMU - addressed in versions 12.4.11, 12.6.7, 12.7.2, 13.2.3
SDM600 - update to 1.2 FP2 HF10
openldap2-ppolicy-check-password-debuginfo - addressed in versions 1.2-9.48.1, 1.2-18.83.1
openldap2-ppolicy-check-password - addressed in versions 1.2-9.48.1, 1.2-18.83.1
compat-libldap-2_3-0 - addressed in versions 2.3.37-2.74.26.1, 2.3.37-39.1
compat-libldap-2_3-0-debuginfo - update to 2.3.37-39.1
openldap2-back-meta - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client-debuginfo - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-openssl1-2_4-2-x86 - update to 2.4.26-0.74.26.1
libldap-openssl1-2_4-2-32bit - update to 2.4.26-0.74.26.1
openldap2-openssl1 - update to 2.4.26-0.74.26.1
openldap2-client-openssl1 - update to 2.4.26-0.74.26.1
libldap-openssl1-2_4-2 - update to 2.4.26-0.74.26.1
libldap-2_4-2-32bit - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-debugsource - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2 - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-2_4-2 - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client-debugsource - update to 2.4.26-0.74.26.1
openldap2-client-openssl1-debugsource - update to 2.4.26-0.74.26.1
openldap2-client-openssl1-debuginfo - update to 2.4.26-0.74.26.1
openldap2-debuginfo - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap (Ubuntu package) - update to 2.4.31-1+nmu2ubuntu8.5+esm8
openldap - update to 2.4.40-16.36
openldap2-back-perl - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-back-perl-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-devel - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-devel-static - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-back-meta-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-2_4-2-debuginfo-32bit - update to 2.4.41-18.83.1
libldap-2_4-2-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-doc - update to 2.4.41-18.83.1
slapd (Ubuntu package) - addressed in versions 2.4.42+dfsg-2ubuntu3.12, 2.4.45+dfsg-1ubuntu1.9, 2.4.49+dfsg-2ubuntu1.6, 2.4.53+dfsg-1ubuntu1.3
libldap-data - update to 2.4.46-9.48.1
libldap-2_4-2-32bit-debuginfo - update to 2.4.46-9.48.1
openldap2-devel-32bit - update to 2.4.46-9.48.1
openldap-help - update to 2.4.50-3
openldap-devel - update to 2.4.50-3
openldap-clients - update to 2.4.50-3
openldap-debuginfo - update to 2.4.50-3
openldap-debugsource - update to 2.4.50-3
openldap - update to 2.4.50-3
openldap-servers - update to 2.4.50-3
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.240
openldap (Debian package) - update to 2.4.47+dfsg-3+deb10u5
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
macOS - addressed in versions 10.14.6 18G9216, 10.15.7 19H1217, 11.4 20F71
RTU500 CMU - addressed in versions 12.4.11, 12.6.7, 12.7.2, 13.2.3
SDM600 - update to 1.2 FP2 HF10
openldap2-ppolicy-check-password-debuginfo - addressed in versions 1.2-9.48.1, 1.2-18.83.1
openldap2-ppolicy-check-password - addressed in versions 1.2-9.48.1, 1.2-18.83.1
compat-libldap-2_3-0 - addressed in versions 2.3.37-2.74.26.1, 2.3.37-39.1
compat-libldap-2_3-0-debuginfo - update to 2.3.37-39.1
openldap2-back-meta - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client-debuginfo - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-openssl1-2_4-2-x86 - update to 2.4.26-0.74.26.1
libldap-openssl1-2_4-2-32bit - update to 2.4.26-0.74.26.1
openldap2-openssl1 - update to 2.4.26-0.74.26.1
openldap2-client-openssl1 - update to 2.4.26-0.74.26.1
libldap-openssl1-2_4-2 - update to 2.4.26-0.74.26.1
libldap-2_4-2-32bit - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-debugsource - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2 - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-2_4-2 - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-client-debugsource - update to 2.4.26-0.74.26.1
openldap2-client-openssl1-debugsource - update to 2.4.26-0.74.26.1
openldap2-client-openssl1-debuginfo - update to 2.4.26-0.74.26.1
openldap2-debuginfo - addressed in versions 2.4.26-0.74.26.1, 2.4.41-18.83.1, 2.4.46-9.48.1
openldap (Ubuntu package) - update to 2.4.31-1+nmu2ubuntu8.5+esm8
openldap - update to 2.4.40-16.36
openldap2-back-perl - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-back-perl-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-devel - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-devel-static - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-back-meta-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
libldap-2_4-2-debuginfo-32bit - update to 2.4.41-18.83.1
libldap-2_4-2-debuginfo - addressed in versions 2.4.41-18.83.1, 2.4.46-9.48.1
openldap2-doc - update to 2.4.41-18.83.1
slapd (Ubuntu package) - addressed in versions 2.4.42+dfsg-2ubuntu3.12, 2.4.45+dfsg-1ubuntu1.9, 2.4.49+dfsg-2ubuntu1.6, 2.4.53+dfsg-1ubuntu1.3
libldap-data - update to 2.4.46-9.48.1
libldap-2_4-2-32bit-debuginfo - update to 2.4.46-9.48.1
openldap2-devel-32bit - update to 2.4.46-9.48.1
openldap-help - update to 2.4.50-3
openldap-devel - update to 2.4.50-3
openldap-clients - update to 2.4.50-3
openldap-debuginfo - update to 2.4.50-3
openldap-debugsource - update to 2.4.50-3
openldap - update to 2.4.50-3
openldap-servers - update to 2.4.50-3
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.240
External References
- https://bugs.openldap.org/show_bug.cgi?id=9425
- https://git.openldap.org/openldap/openldap/-/commit/4bdfffd2889c0c5cdf58bebafbdc8fce4bb2bff0
- https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
- https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html
- https://www.debian.org/security/2021/dsa-4845
Related Security Bulletins
- Multiple vulnerabilities in OpenLDAP
- Debian update for openldap
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple macOS Mojave
- Multiple vulnerabilities in Apple macOS Catalina
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Hitachi Energy RTU500 series CMU
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in Hitachi Energy SDM600
- SUSE update for openldap2
- Ubuntu update for openldap
- SUSE update for openldap2
- SUSE update for openldap2
- SUSE update for openldap2
- Amazon Linux AMI update for openldap
- openEuler update for openldap
- Splunk Enterprise update for third-party components
- Ubuntu update for openldap