CVE-2020-25710

HIGH

OpenLDAP < 2.4.56 - Denial of Service via csnNormalize23() Assertion Failure

Title source: llm
STIX 2.1

Description

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 7.5
EPSS 0.1746
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-617
Status published
Products (9)
debian/debian_linux 9.0
fedoraproject/fedora 33
openldap/openldap < 2.4.56
redhat/enterprise_linux 5.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/jboss_core_services
redhat/jboss_enterprise_application_platform 5.0.0
redhat/jboss_enterprise_web_server 2.0.0
Published May 28, 2021
Tracked Since Feb 18, 2026