A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openldap | Openldap | * | 2.4.57 (excluding) |
Openldap | Ubuntu | bionic | * |
Openldap | Ubuntu | devel | * |
Openldap | Ubuntu | esm-infra-legacy/trusty | * |
Openldap | Ubuntu | focal | * |
Openldap | Ubuntu | groovy | * |
Openldap | Ubuntu | hirsute | * |
Openldap | Ubuntu | impish | * |
Openldap | Ubuntu | jammy | * |
Openldap | Ubuntu | kinetic | * |
Openldap | Ubuntu | lunar | * |
Openldap | Ubuntu | mantic | * |
Openldap | Ubuntu | noble | * |
Openldap | Ubuntu | oracular | * |
Openldap | Ubuntu | precise/esm | * |
Openldap | Ubuntu | trusty | * |
Openldap | Ubuntu | trusty/esm | * |
Openldap | Ubuntu | upstream | * |
Openldap | Ubuntu | xenial | * |