imPC@ndo IT

Tracker / CVE-2020-36230

CVE-2020-36230

High 7.5

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

Affected products and versions

apache bookkeeper
apple mac_os_x
apple mac_os_x · 10.14.0 → 10.14.6
apple macos · 11.1 → 11.4
debian debian_linux
openldap openldap · … → 2.4.57

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References