漏洞信息详情
OpenLDAP 代码问题漏洞
漏洞简介
OpenLDAP是美国OpenLDAP(Openldap)基金会的一个轻型目录访问协议(LDAP)的开源实现。TCP(Transmission Control Protocol,传输控制协议)是一种面向连接的、可靠的、基于字节流的传输层通信协议,由IETF的RFC 793定义。
Openldap 2.4.55之前版本存在代码问题漏洞,该漏洞源于null-ptr指针取消引用。收到恶意TCP数据包后,造成OpenLDAP slapd崩溃。
漏洞公告
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:
https://git.openldap.org/openldap/openldap/-/commit/4c774220a752bf8e3284984890dc0931fe73165d
参考网址
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1894567
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210108-0006/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4032/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021053006
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160032/Ubuntu-Security-Notice-USN-4622-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4057/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-25692
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3713
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1754
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159962/Ubuntu-Security-Notice-USN-4622-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162721/Red-Hat-Security-Advisory-2021-2053-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-affected-by-an-openldap-vulnerability-cve-2020-25692/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6479911
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3340
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164452/Red-Hat-Security-Advisory-2021-3748-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1432
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-openldap-vulnerability-cve-2020-25692/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162354/Red-Hat-Security-Advisory-2021-1389-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2180
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-network-packet-capture-is-vulnerable-to-using-components-with-known-vulnerabilities-2/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6514401
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021050606
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...