CVE-2020-36221
HIGH | Platform: macOS | Changelog
CVE Details
Description
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Weakness
References
- Apple Security Advisory
- NVD Entry
- http://seclists.org/fulldisclosure/2021/May/64 (Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2021/May/65 (Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2021/May/70 (Mailing List, Third Party Advisory)
- https://bugs.openldap.org/show_bug.cgi?id=9404 (Issue Tracking, Vendor Advisory)
- https://bugs.openldap.org/show_bug.cgi?id=9424 (Issue Tracking, Vendor Advisory)
- https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31 (Patch, Vendor Advisory)
- https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842 (Patch, Vendor Advisory)
- https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57 (Release Notes, Vendor Advisory)