NULL pointer dereference in OpenLDAP - CVE-2023-2953

 

NULL pointer dereference in OpenLDAP - CVE-2023-2953

Published: June 13, 2023


Vulnerability identifier: #VU77252
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2953
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the ber_memalloc_x() function. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

OpenLDAP
Oracle Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
F5OS
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Legacy Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
DataStax Hyper-Converged Database
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
ObjectScale
Platform Automation Toolkit
IBM QRadar Incident Forensics
Dell PowerProtect Cyber Recovery
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Cryostat
Oracle Communications Cloud Native Core Certificate Management
Cluster Observability Operator
Submariner
Migration Toolkit for Runtimes
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Cloud Pak for Business Automation
Voice Gateway
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
slapd (Ubuntu package)
openldap2-ppolicy-check-password-debuginfo
openldap2-ppolicy-check-password
compat-libldap-2_3-0-debuginfo
compat-libldap-2_3-0
openldap
openldap2-client
openldap2-back-meta-debuginfo
openldap2-client-debuginfo
openldap2-back-meta
libldap-2_4-2
openldap2
libldap-2_4-2-debuginfo
openldap2-devel
openldap2-debugsource
openldap2-debuginfo
openldap2-back-perl
openldap2-devel-static
openldap2-back-perl-debuginfo
openldap2-doc
libldap-2_4-2-debuginfo-32bit
libldap-2_4-2-32bit
openldap-devel
openldap-clients
openldap-servers
openldap2-back-sql-debuginfo
openldap2-contrib-debuginfo
openldap2-back-sock
openldap2-contrib
openldap2-back-sock-debuginfo
libldap-data
openldap2-devel-32bit
libldap-2_4-2-32bit-debuginfo
openldap2-back-sql
openldap-debugsource
openldap-debuginfo
openldap-help
openldap (Red Hat package)
BIG-IP
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Console
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Security Verify Access
IBM CICS TX Advanced

How to mitigate CVE-2023-2953

Install updates from vendor's website.

OpenLDAP - update to 2.5.14
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Voice Gateway - update to 1.0.8.12
DataStax Hyper-Converged Database - update to 1.2.5
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Qradar SIEM - addressed in versions 7.5.0 Update Pack 9 IF01, 7.5.0 Update Pack 10
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
slapd (Ubuntu package) - addressed in versions Ubuntu Pro, 2.4.49+dfsg-2ubuntu1.10, 2.5.16+dfsg-0ubuntu0.22.04.2
Cluster Observability Operator - update to 0.4.1
Submariner - update to 0.17.6
Red Hat OpenShift Serverless - update to 1
Migration Toolkit for Runtimes - update to 1.2.7
openldap2-ppolicy-check-password-debuginfo - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
openldap2-ppolicy-check-password - addressed in versions 1.2-22.19.1, 1.2-150200.14.14.1
ObjectScale - update to 1.4.0
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
compat-libldap-2_3-0-debuginfo - update to 2.3.37-45.1
compat-libldap-2_3-0 - update to 2.3.37-45.1
Multicluster Engine for Kubernetes - update to 2.4.6
openldap - addressed in versions 2.4.40-16.37, 2.4.57-6
openldap2-client - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-client-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-meta - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2 - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debugsource - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-devel-static - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-back-perl-debuginfo - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap2-doc - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
libldap-2_4-2-debuginfo-32bit - update to 2.4.41-22.19.1
libldap-2_4-2-32bit - addressed in versions 2.4.41-22.19.1, 2.4.46-150200.14.14.1
openldap-devel - update to 2.4.46-19
openldap-clients - update to 2.4.46-19
openldap - update to 2.4.46-19
openldap-servers - update to 2.4.46-19
openldap2-back-sql-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-contrib-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sock - update to 2.4.46-150200.14.14.1
openldap2-contrib - update to 2.4.46-150200.14.14.1
openldap2-back-sock-debuginfo - update to 2.4.46-150200.14.14.1
libldap-data - update to 2.4.46-150200.14.14.1
openldap2-devel-32bit - update to 2.4.46-150200.14.14.1
libldap-2_4-2-32bit-debuginfo - update to 2.4.46-150200.14.14.1
openldap2-back-sql - update to 2.4.46-150200.14.14.1
openldap - update to 2.4.50-8
openldap-clients - update to 2.4.50-8
openldap-debugsource - update to 2.4.50-8
openldap-debuginfo - update to 2.4.50-8
openldap-devel - update to 2.4.50-8
openldap-servers - update to 2.4.50-8
openldap-help - update to 2.4.50-8
openldap (Red Hat package) - addressed in versions 2.6.2-1.el9_0.1, 2.6.2-3.el9_2.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5
VMware Tanzu Operations Manager - update to 2.10.60
VMware Tanzu Application Service for VMs - addressed in versions 3.0.14, 4.0.5
Isolation Segment - addressed in versions 3.0.14, 4.0.5
Red Hat OpenShift Dev Spaces - update to 3.15.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.77, 4.13.45, 4.14.32, 4.14.33, 4.14.53, 4.15.21, 4.15.52
OpenShift Logging - update to 5.6.21
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Security Verify Access - update to 10.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix27
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001

External References

Related Security Bulletins