#VU50389 Integer underflow in OpenLDAP - CVE-2020-36221
Published: January 26, 2021 / Updated: February 5, 2021
OpenLDAP
OpenLDAP.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer underflow within the serialNumberAndIssuerCheck() function in schema_init.c. A remote attacker can send a specially crafted request to the affected application, trigger an integer underflow and crash the slapd.
Remediation
External links
- https://bugs.openldap.org/show_bug.cgi?id=9404
- https://bugs.openldap.org/show_bug.cgi?id=9424
- https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31
- https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842
- https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
- https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html
- https://www.debian.org/security/2021/dsa-4845