First published: Mon May 29 2023(Updated: )
A vulnerability was found in openldap that can cause a null pointer dereference in the ber_memalloc_x() function.
Credit: secalert@redhat.com secalert@redhat.com Sandipan Roy Sandipan Roy Sandipan Roy secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Big Sur | <11.7.9 | 11.7.9 |
Apple macOS Ventura | <13.5 | 13.5 |
Apple macOS Monterey | <12.6.8 | 12.6.8 |
Openldap Openldap | =2.4 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Apple macOS | >=11.0<11.7.9 | |
Apple macOS | >=12.0<12.6.8 | |
Apple macOS | >=13.0<13.5 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
NetApp Clustered Data ONTAP | ||
Netapp Ontap Tools Vmware Vsphere | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
All of | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
All of | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
All of | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
All of | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
All of | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
debian/openldap | <=2.4.57+dfsg-3+deb11u1<=2.5.13+dfsg-5 | 2.5.18+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The CVE ID of this vulnerability is CVE-2023-2953.
The severity level of CVE-2023-2953 is high (7).
The affected software includes OpenLDAP version 2.4, Redhat Enterprise Linux versions 8.0 and 9.0, Apple macOS versions 11.0 to 11.7.9, Apple macOS versions 12.0 to 12.6.8, and Apple macOS versions 13.0 to 13.5.
The vulnerability causes a null pointer dereference in the ber_memalloc_x() function of OpenLDAP.
To mitigate this vulnerability, apply the patches provided by the respective vendors or upgrade to a non-vulnerable version of the affected software.