PT-2021-5533 · Openldap+7 · Openldap+7

Published

2021-01-25

·

Updated

2025-08-17

·

CVE-2020-36226

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.57
Description A flaw in OpenLDAP leads to a memch->bv len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service. The issue is related to a resource management error. An attacker can exploit this flaw by sending a specially crafted request to slapd, allowing them to perform a denial of service attack.
Recommendations For OpenLDAP versions prior to 2.4.57, this issue was addressed with improved checks, implying that updating to version 2.4.57 or later should resolve the issue. As a temporary workaround, consider restricting access to the saslAuthzTo processing in slapd to minimize the risk of exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1333
ALT-PU-2021-1352
ALT-PU-2021-1354
BDU:2021-06383
BIT-OPENLDAP-2020-36226
CVE-2020-36226
DLA-2544-1
DSA-4845-1
MGASA-2021-0105
OESA-2021-1062
OPENSUSE-SU-2021:0408-1
OPENSUSE-SU-2021_0408-1
ROSA-SA-2025-2550
SUSE-SU-2021:0692-1
SUSE-SU-2021:0693-1
SUSE-SU-2021:0723-1
SUSE-SU-2021:14700-1
SUSE-SU-2021_14700-1
USN-4724-1
USN-7698-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Apple Macos
Openldap
Red Os
Suse
Ubuntu