PT-2020-14606 · Openldap+3 · Openldap+3
Published
2019-04-21
·
Updated
2024-03-06
·
CVE-2020-15719
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenLDAP versions prior to 2.4.46-10.el8
Description
The issue is related to a certificate-validation flaw in libldap when asserting RFC6125 support. Specifically, it considers the Common Name (CN) even when there is a non-matching subjectAltName (SAN).
Recommendations
For versions prior to 2.4.46-10.el8, update to a version that includes the fix, such as openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Openldap
Suse