PT-2021-5544 · Openldap+6 · Openldap+6

Padma81

·

Published

2021-02-14

·

Updated

2025-08-24

·

CVE-2021-27212

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenLDAP versions 2.4.57 and 2.5.x through 2.5.1alpha
Description The issue is related to an assertion failure in the issuerAndThisUpdateCheck function, which can occur via a crafted packet with a short timestamp, resulting in a denial of service (daemon exit). This is related to schema init.c and checkTime. The vulnerability can be exploited by a remote attacker, allowing them to send a specially crafted packet to slapd and execute a denial of service attack.
Recommendations For OpenLDAP versions 2.4.57 and 2.5.x through 2.5.1alpha, consider disabling the issuerAndThisUpdateCheck function as a temporary workaround until a patch is available. Restrict access to the schema init.c and checkTime components to minimize the risk of exploitation. Avoid using crafted packets with short timestamps in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Assertion Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2530
ALT-PU-2021-2578
ALT-PU-2021-2585
ALT-PU-2021-2680
AZL-6771
BDU:2021-06394
BIT-OPENLDAP-2021-27212
CVE-2021-27212
DLA-2574-1
DSA-4860-1
MGASA-2021-0105
OESA-2021-1119
OPENSUSE-SU-2021:0408-1
OPENSUSE-SU-2021_0408-1
ROSA-SA-2025-2550
SUSE-SU-2021:0692-1
SUSE-SU-2021:0693-1
SUSE-SU-2021:0723-1
SUSE-SU-2021:14700-1
SUSE-SU-2021_14700-1
USN-4744-1
USN-7713-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openldap
Red Os
Suse
Ubuntu