Lucene search

K
f5F5F5:K56241216
HistoryMar 31, 2022 - 12:00 a.m.

K56241216 : OpenLDAP vulnerabilities CVE-2020-25709 and CVE-2020-25710

2022-03-3100:00:00
my.f5.com
18
openldap
cve-2020-25709
cve-2020-25710
assertion failure
denial-of-service
system availability

AI Score

7.6

Confidence

High

EPSS

0.028

Percentile

90.7%

Security Advisory Description

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

Impact

A successful exploit of these vulnerabilities may lead to a denial-of-service (DoS).