Vulnerability Name:

CVE-2020-25709 (CCN-192486)

Assigned:2020-11-02
Published:2020-11-02
Updated:2021-09-14
Summary:A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-617
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-25709

Source: FULLDISC
Type: Mailing List, Third Party Advisory
20210201 APPLE-SA-2021-02-01-1 macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave

Source: CCN
Type: OpenLDAP Web site
OpenLDAP

Source: CCN
Type: Red Hat Bugzilla – Bug 1899675
(CVE-2020-25709) - CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1899675

Source: XF
Type: UNKNOWN
openldap-cve202025709-dos(192486)

Source: CCN
Type: OpenLDAP GIT Repository
OpenLDAP

Source: MLIST
Type: Mailing List, Third Party Advisory
[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8

Source: MLIST
Type: Mailing List, Third Party Advisory
[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20201204 [SECURITY] [DLA 2481-1] openldap security update

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20210716-0003/

Source: CCN
Type: Apple security document HT212147
About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave

Source: CONFIRM
Type: Third Party Advisory
https://support.apple.com/kb/HT212147

Source: DEBIAN
Type: Third Party Advisory
DSA-4792

Source: CCN
Type: IBM Security Bulletin 6551876 (Cloud Pak for Security)
Cloud Pak for Security uses packages that are vulnerable to multiple CVEs

Source: CCN
Type: IBM Security Bulletin 6568365 (QRadar Network Packet Capture)
IBM QRadar Network Packet Capture is using components with known vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6601951 (QRadar Network Security)
IBM QRadar Network Security is affected by vulnerabilities in openldap. (CVE-2020-25709, CVE-2020-25710)

Source: CCN
Type: IBM Security Bulletin 6605875 (Security Access Manager Appliance)
Security Vulnerabilities have been fixed in IBM Security Access Manager appliance (CVE-2022-24407, CVE-2020-25709, CVE-2020-25710)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openldap:openldap:*:*:*:*:*:*:*:* (Version < 2.4.56)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version >= 10.14.0 and < 10.14.6)
  • OR cpe:/o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-004:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-005:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-006:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2019-007:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-001:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-002:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-003:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-004:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-005:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-006:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.14.6:security_update_2020-007:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version >= 10.15 and < 10.15.7)
  • OR cpe:/o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-005:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.15.7:security_update_2020-007:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*
  • OR cpe:/o:apple:macos:*:*:*:*:*:*:*:* (Version >= 11.0 and < 11.0.1)

  • Configuration 4:
  • cpe:/a:redhat:jboss_core_services:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openldap:openldap:-:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:qradar_network_security:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_security:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_packet_capture:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager_appliance_firmware:9.0.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_access_manager:9.0.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8047
    P
    openldap2-devel-32bit-2.4.46-150200.14.11.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7609
    P
    libldap-2_4-2-2.4.46-150200.14.11.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3390
    P
    unrar-5.0.14-3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3024
    P
    bind-9.11.2-3.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3412
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95042
    P
    openldap2-devel-32bit-2.4.46-150200.14.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94502
    P
    avahi-0.8-150400.5.73 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94881
    P
    ImageMagick-7.1.0.9-150400.4.7 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94654
    P
    libldap-2_4-2-2.4.46-150200.14.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95207
    P
    libopencv3_4-3.4.16-150400.1.9 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1080
    P
    Security update for ImageMagick (Moderate) (in QA)
    2022-06-16
    oval:org.opensuse.security:def:151
    P
    libldap-2_4-2-2.4.46-9.51.1 on GA media (Moderate)
    2022-06-13
    oval:com.redhat.rhsa:def:20220621
    P
    RHSA-2022:0621: openldap security update (Moderate)
    2022-02-22
    oval:org.opensuse.security:def:101594
    P
    Security update for permissions (Moderate)
    2022-01-20
    oval:org.opensuse.security:def:101920
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:4472
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 12 SP5) (Important)
    2021-08-17
    oval:org.opensuse.security:def:2009
    P
    openldap2-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63098
    P
    openldap2-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:71910
    P
    libldap-2_4-2-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62169
    P
    libldap-2_4-2-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72747
    P
    openldap2-devel-32bit-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100927
    P
    libldap-2_4-2-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1939
    P
    openldap2-devel-32bit-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63028
    P
    openldap2-devel-32bit-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101286
    P
    openldap2-devel-32bit-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101215
    P
    libquicktime-1.2.4+git20180804.fff99cd-1.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:102286
    P
    Security update for the Linux Kernel (Important)
    2021-06-15
    oval:org.opensuse.security:def:110979
    P
    Security update for openldap2 (Moderate)
    2021-01-18
    oval:org.opensuse.security:def:110646
    P
    Security update for openldap2 (Moderate)
    2021-01-17
    oval:org.opensuse.security:def:24058
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:23152
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:51879
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:49186
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:4748
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:23564
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:52046
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:51140
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:23891
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:125524
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:20715
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:51552
    P
    Security update for openldap2 (Moderate)
    2021-01-15
    oval:org.opensuse.security:def:67535
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:37511
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:60236
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:96866
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:45071
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:100270
    P
    (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:95573
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:64479
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:108260
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:117774
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:75816
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:26034
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:39264
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:87366
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:65561
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:108586
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:117875
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:42796
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:5659
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:32902
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:40641
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:5021
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:73601
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:66748
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:108952
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:58725
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:43694
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:6446
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:34413
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:107881
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:117396
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:74629
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    BACK
    openldap openldap *
    debian debian linux 9.0
    debian debian linux 10.0
    apple mac os x *
    apple mac os x 10.14.6 -
    apple mac os x 10.14.6 security_update_2019-004
    apple mac os x 10.14.6 security_update_2019-005
    apple mac os x 10.14.6 security_update_2019-006
    apple mac os x 10.14.6 security_update_2019-007
    apple mac os x 10.14.6 security_update_2020-001
    apple mac os x 10.14.6 security_update_2020-002
    apple mac os x 10.14.6 security_update_2020-003
    apple mac os x 10.14.6 security_update_2020-004
    apple mac os x 10.14.6 security_update_2020-005
    apple mac os x 10.14.6 security_update_2020-006
    apple mac os x 10.14.6 security_update_2020-007
    apple mac os x *
    apple mac os x 10.15.7 -
    apple mac os x 10.15.7 security_update_2020-005
    apple mac os x 10.15.7 security_update_2020-007
    apple mac os x 10.15.7 supplemental_update
    apple macos *
    redhat jboss core services -
    openldap openldap -
    ibm qradar network security 5.4.0
    ibm qradar network security 5.5.0
    ibm qradar network packet capture 7.3
    ibm security access manager appliance firmware 9.0.7.0
    ibm security access manager 9.0.7.1
    ibm cloud pak for security 1.7.2.0