VDB
BIT-openldap-2020-12243
BIT-openldap-2020-12243
PUBLISHED
CVSS 7.5 HIGH
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | openldap | 0, 0, 0 |
Timeline
- Mar 6, 2024 CVE Published
- Apr 3, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html url
- https://bugs.openldap.org/show_bug.cgi?id=9202 url
- https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_4/CHANGES url
- https://git.openldap.org/openldap/openldap/-/commit/98464c11df8247d6a11b52e294ba5dd4f0380440 url
- https://lists.debian.org/debian-lts-announce/2020/05/msg00001.html url
- https://security.netapp.com/advisory/ntap-20200511-0003/ url
- https://support.apple.com/kb/HT211289 url
- https://usn.ubuntu.com/4352-1/ url
- https://usn.ubuntu.com/4352-2/ url
- https://www.debian.org/security/2020/dsa-4666 url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-12243 url