CVE-2021-27212 describes a denial-of-service vulnerability affecting OpenLDAP versions through 2.4.57 and 2.5.x through 2.5.1alpha, specifically impacting Debian Linux distributions. This flaw allows an unauthenticated attacker to cause the slapd daemon to crash by sending a specially crafted packet with a short timestamp, triggering an assertion failure. Rated with a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to a complete loss of availability. While the EPSS score indicates a moderate likelihood of exploitation, there is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.57CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:2.5.0:alpha:*:*:*:*:*:* | ||
2.5.1CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:2.5.1:alpha:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - October 2024
Oct 14, 2024openldap: Assertion failure in slapd in the issuerAndThisUpdateCheck function
Feb 14, 2021In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
Feb 9, 2021