PT-2021-5552 · Openldap+7 · Openldap+7

Published

2021-01-25

·

Updated

2025-08-17

·

CVE-2020-36228

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.57
Description An integer underflow was discovered in the Certificate List Exact Assertion processing, resulting in a denial of service. This issue can be exploited by a remote attacker, allowing them to send a specially crafted request to the slapd application, causing an integer underflow and leading to a crash.
Recommendations For versions prior to 2.4.57, update to version 2.4.57 or later to resolve the issue. As a temporary workaround, consider restricting access to the Certificate List Exact Assertion processing to minimize the risk of exploitation.

Fix

DoS

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1333
ALT-PU-2021-1352
ALT-PU-2021-1354
BDU:2021-06402
BIT-OPENLDAP-2020-36228
CVE-2020-36228
DLA-2544-1
DSA-4845-1
MGASA-2021-0105
OESA-2021-1062
OPENSUSE-SU-2021:0408-1
OPENSUSE-SU-2021_0408-1
ROSA-SA-2025-2550
SUSE-SU-2021:0692-1
SUSE-SU-2021:0693-1
SUSE-SU-2021:0723-1
SUSE-SU-2021:14700-1
SUSE-SU-2021_14700-1
USN-4724-1
USN-7698-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Apple Macos
Openldap
Red Os
Suse
Ubuntu