PublicDateAtUSN: 2020-11-13 00:00:00 UTC Candidate: CVE-2020-25709 PublicDate: 2021-05-18 12:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25709 https://ubuntu.com/security/notices/USN-4634-1 https://ubuntu.com/security/notices/USN-4634-2 Description: A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability. Ubuntu-Description: Notes: Mitigation: Bugs: https://bugs.openldap.org/show_bug.cgi?id=9383 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_openldap: upstream: https://git.openldap.org/openldap/openldap/-/commit/67670f4544e28fb09eb7319c39f404e1d3229e65 upstream_openldap: released (2.4.56+dfsg-1) precise/esm_openldap: released (2.4.28-1.1ubuntu4.12) trusty_openldap: ignored (out of standard support) trusty/esm_openldap: released (2.4.31-1+nmu2ubuntu8.5+esm4) xenial_openldap: released (2.4.42+dfsg-2ubuntu3.11) esm-infra/xenial_openldap: released (2.4.42+dfsg-2ubuntu3.11) bionic_openldap: released (2.4.45+dfsg-1ubuntu1.8) focal_openldap: released (2.4.49+dfsg-2ubuntu1.5) groovy_openldap: released (2.4.53+dfsg-1ubuntu1.2) devel_openldap: released (2.4.53+dfsg-1ubuntu5)