CVE-2021-27212
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 64.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 64.15% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- openldap/openldap · debian/debian linux
- Source
- cve@mitre.org
References
- https://bugs.openldap.org/show_bug.cgi?id=9454Exploit, Issue Tracking, Vendor Advisory
- https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0Patch, Vendor Advisory
- https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30Patch, Vendor Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/02/msg00035.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210319-0005/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4860Third Party Advisory
- https://bugs.openldap.org/show_bug.cgi?id=9454Exploit, Issue Tracking, Vendor Advisory
- https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0Patch, Vendor Advisory
- https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30Patch, Vendor Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/02/msg00035.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210319-0005/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4860Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.