漏洞信息详情
OpenLDAP 数字错误漏洞
漏洞简介
OpenLDAP是美国OpenLDAP(Openldap)基金会的一个轻型目录访问协议(LDAP)的开源实现。
OpenLDAP 2.4.57版本之前存在数字错误漏洞。该漏洞源于程序在发现整数下溢后,导致证书列表精确声明处理中发生严重崩溃。攻击者可以利用该漏洞导致拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
参考网址
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/65
来源:MLIST
链接:https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/64
来源:CONFIRM
链接:https://support.apple.com/kb/HT212529
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2021/May/70
来源:MISC
链接:https://bugs.openldap.org/show_bug.cgi?id=9427
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210226-0002/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html
来源:MISC
链接:https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad
来源:MLIST
链接:https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4845
来源:MISC
链接:https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57
来源:CONFIRM
链接:https://support.apple.com/kb/HT212531
来源:CONFIRM
链接:https://support.apple.com/kb/HT212530
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0828
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162820/Apple-Security-Advisory-2021-05-25-4.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-36228
来源:support.apple.com
链接:https://support.apple.com/en-us/HT212529
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1794
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092209
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052502
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161318/Ubuntu-Security-Notice-USN-4724-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1305
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0788
来源:support.apple.com
链接:https://support.apple.com/en-us/HT212531
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0429
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...