漏洞信息详情
OpenLDAP 安全漏洞
- CNNVD编号:CNNVD-202101-2289
- 危害等级: 高危
- CVE编号: CVE-2020-36227
- 漏洞类型: 其他
- 发布时间: 2021-01-26
- 威胁类型: 远程
- 更新时间: 2021-12-30
- 厂 商:
- 漏洞来源: Ubuntu
漏洞简介
OpenLDAP是美国OpenLDAP(Openldap)基金会的一个轻型目录访问协议(LDAP)的开源实现。
OpenLDAP 2.4.57版本之前存在安全漏洞。该漏洞源于cancel_extop Cancel操作在无限循环中发生。攻击者可以利用该漏洞导致拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
参考网址
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/65
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/64
来源:CONFIRM
链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212529
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/70
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210226-0002/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/02/msg00005.HTML
来源:MLIST
链接:https://lists.apache.org/thread.HTML/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4845
来源:MISC
链接:https://bugs.openldap.org/show_bug.cgi?id=9428
来源:MISC
链接:https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
来源:MISC
链接:https://git.openldap.org/openldap/openldap/-/commit/9d0e8485f3113505743baabf1167e01e4558ccf5
来源:CONFIRM
链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212531
来源:CONFIRM
链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kb/HT212530
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0828
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162820/CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-Security-Advisory-2021-05-25-4.HTML
来源:support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com
链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/en-us/HT212529
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052502
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1305
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0788
来源:support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com
链接:https://support.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/en-us/HT212531
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0429
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-36227
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1794
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092209
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161318/Ubuntu-Security-Notice-USN-4724-1.HTML
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021122914
受影响实体
暂无
补丁
暂无
评论