CVE-2020-25692: Null Pointer Dereference
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
Other sources
OpenLDAP is vulnerable to a denial of service, caused by a NULL pointer dereference. By sending a specially crafted TCP packet, a remote attacker could exploit this vulnerability to cause slapd to crash.
— IBM
OpenLDAP slapd crashes on what seems to be a null-ptr-dereference after receiving a malicious TCP packet.
Reference: https://bugs.openldap.org/showbug.cgi?id=9370
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-25692?
CVE-2020-25692 is a vulnerability found in OpenLDAP server that allows an unauthenticated attacker to remotely crash the slapd process, causing a Denial of Service.
How does CVE-2020-25692 affect OpenLDAP?
CVE-2020-25692 affects OpenLDAP server versions up to and including 2.4.55.
What is the severity rating of CVE-2020-25692?
CVE-2020-25692 has a severity rating of 7.5, which is considered high.
How can I fix CVE-2020-25692?
To fix CVE-2020-25692, you need to update to OpenLDAP version 2.4.55 or higher.
Where can I find more information about CVE-2020-25692?
You can find more information about CVE-2020-25692 in the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1894567), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20210108-0006/), [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/191968).