Lucene search

K
osvGoogleOSV:USN-4888-2
HistoryMar 25, 2021 - 3:32 p.m.

ldb vulnerabilities

2021-03-2515:32:21
Google
osv.dev
11
usn-4888-1
ldb
ubuntu 14.04 esm
samba
ldap
cve-2021-20277
cve-2020-27840

AI Score

8.2

Confidence

High

EPSS

0.009

Percentile

82.7%

USN-4888-1 fixed several vulnerabilities in ldb. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

Douglas Bagnall discovered that ldb, when used with Samba, incorrectly
handled certain LDAP attributes. A remote attacker could possibly use this
issue to cause the LDAP server to crash, resulting in a denial of service.
(CVE-2021-20277)

Douglas Bagnall discovered that ldb, when used with Samba, incorrectly
handled certain DN strings. A remote attacker could use this issue to
cause the LDAP server to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-27840)