7.5
CVE-2020-12243
- EPSS 4.42%
- Veröffentlicht 28.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:22
- Erkennungen
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 12.04
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Netapp ≫ Cloud Backup Version -
Netapp ≫ Steelstore Cloud Integrated Storage Version -
Netapp ≫ H410c Firmware Version -
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H300e Firmware Version -
Netapp ≫ H500e Firmware Version -
Netapp ≫ H700e Firmware Version -
Netapp ≫ H410s Firmware Version -
Broadcom ≫ Brocade Fabric Operating System Version -
Oracle ≫ Zfs Storage Appliance Kit Version 8.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.42% | 0.901 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-674 Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://support.apple.com/kb/HT211289
https://www.oracle.com/security-alerts/cpuoct2020.html
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html
https://bugs.openldap.org/show_bug.cgi?id=9202
https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES
https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440
https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html
https://security.netapp.com/advisory/ntap-20200511-0003/
https://usn.ubuntu.com/4352-1/
https://usn.ubuntu.com/4352-2/
https://www.debian.org/security/2020/dsa-4666