Lucene search

K
osvGoogleOSV:USN-5424-2
HistoryMay 19, 2022 - 2:39 p.m.

openldap vulnerability

2022-05-1914:39:17
Google
osv.dev
8
openldap
sql injection
ubuntu 14.04
ubuntu 16.04

AI Score

9.9

Confidence

High

EPSS

0.013

Percentile

86.0%

USN-5424-1 fixed a vulnerability in OpenLDAP. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that OpenLDAP incorrectly handled certain SQL statements
within LDAP queries in the experimental back-sql backend. A remote attacker
could possibly use this issue to perform an SQL injection attack and alter
the database.