CVE-2020-25710: High severity red hat openldap servers vulnerability
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
Other sources
A malicious packet can force OpenLDAP to fail an assertion in csnNormalize23 function in servers/slapd/schemainit.c.
Reference: https://bugs.openldap.org/showbug.cgi?id=9384
Upstream patch: https://git.openldap.org/openldap/openldap/-/commit/bdb0d459187522a6063df13871b82ba8dcc6efe2
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw in OpenLDAP?
The vulnerability ID of this flaw in OpenLDAP is CVE-2020-25710.
What is the severity rating of CVE-2020-25710?
The severity rating of CVE-2020-25710 is 7.5 (High).
What is the highest threat from CVE-2020-25710?
The highest threat from CVE-2020-25710 is to system availability.
Which software versions are affected by CVE-2020-25710?
Versions of OpenLDAP before 2.4.56 are affected by CVE-2020-25710.
Where can I find more information about CVE-2020-25710?
You can find more information about CVE-2020-25710 at the following references: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=1899678), [Link 2](https://git.openldap.org/openldap/openldap/-/commit/ab3915154e69920d480205b4bf5ccb2b391a0a1f#a2feb6ed0257c21c6672793ee2f94eaadc10c72c), [Link 3](https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E).