PublicDateAtUSN: 2021-01-26 18:15:00 UTC Candidate: CVE-2020-36228 PublicDate: 2021-01-26 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36228 https://ubuntu.com/security/notices/USN-4724-1 Description: An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. Ubuntu-Description: Notes: Mitigation: Bugs: https://bugs.openldap.org/show_bug.cgi?id=9427 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_openldap: upstream: https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad upstream_openldap: released (2.4.57+dfsg-1) precise/esm_openldap: ignored (end of ESM support, was needed) trusty_openldap: ignored (out of standard support) trusty/esm_openldap: needed xenial_openldap: released (2.4.42+dfsg-2ubuntu3.12) esm-infra/xenial_openldap: released (2.4.42+dfsg-2ubuntu3.12) bionic_openldap: released (2.4.45+dfsg-1ubuntu1.9) focal_openldap: released (2.4.49+dfsg-2ubuntu1.6) groovy_openldap: released (2.4.53+dfsg-1ubuntu1.3) hirsute_openldap: released (2.4.57+dfsg-2ubuntu1) impish_openldap: released (2.4.57+dfsg-2ubuntu1) jammy_openldap: released (2.4.57+dfsg-2ubuntu1) devel_openldap: released (2.4.57+dfsg-2ubuntu1)