Openldap: community verdicts
5 notable / known-exploited Openldap CVEs the community has triaged.
- CVE-2017-17740HIGH 7.5EPSS 7%
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
- CVE-2015-3276HIGH 7.5EPSS 5%
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
- CVE-2020-15719MED 4.2EPSS 3%
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
- CVE-2023-2953HIGH 7.5Real · low riskEPSS 2%
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
- CVE-2017-14159MED 4.7EPSS 0%
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.