ZeroHour

CVE-2020-25710

CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
Modified
Description

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

Vendors
openldapredhatdebianfedoraproject
Products
openldap, jboss core services, jboss enterprise application platform, jboss enterprise web server, enterprise linux, debian linux, fedora
Weakness
CWE-617
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.