CVE-2020-36221
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 84%
exploitation probability
84%top 1% of all CVEs
observed exploitation
nono source reports it
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
Affected products
n/a · n/aReferences
https://bugs.openldap.org/show_bug.cgi?id=9404https://bugs.openldap.org/show_bug.cgi?id=9424http://seclists.org/fulldisclosure/2021/May/64http://seclists.org/fulldisclosure/2021/May/65http://seclists.org/fulldisclosure/2021/May/70https://git.openldap.org/openldap/openldap/-/commit/38ac838e4150c626bbfa0082b7e2cf3a2bb4df31https://git.openldap.org/openldap/openldap/-/commit/58c1748e81c843c5b6e61648d2a4d1d82b47e842https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/02/msg00005.htmlhttps://security.netapp.com/advisory/ntap-20210226-0002/