Bugzilla – Bug 1186725
VUL-0: CVE-2020-20178: Ethereum 0xe933c0cd9784414d5f278c114904f5a84b396919#code.sol issue
Last modified: 2021-06-21 23:32:38 UTC
https://nvd.nist.gov/vuln/detail/CVE-2020-20178 A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability. https://bugzilla.redhat.com/show_bug.cgi?id=1928774 In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime. References: https://bugs.openldap.org/show_bug.cgi?id=9454 https://git.openldap.org/openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0 https://git.openldap.org/openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30
This is already patched and released in all affected code streams.
weird, the upstgream cve desc fliopped to a ethereum description Ethereum 0xe933c0cd9784414d5f278c114904f5a84b396919#code.sol latest version is affected by a denial of service vulnerability in the affected payout function. Once the length of this array is too long, it will result in an exception. Attackers can make attacks by creating a series of account addresses.
I filed a review request with Mitre. This change of description is usually not acceptable for CNAs.
Okay, I'll leave it with you to follow up - if you still need this added to the changelog then I'll do it once we clear up the cve assignment situation :)
Marcus, William, Looks like MITRE may have corrected an earlier mistake of mapping CVE-2020-20178 to an OpenLDAP vulnerability, which is now having Ethereum description. The OpenLDAP vulnerability is actually another CVE -> CVE-2021-27212. See 1 and 2 below. 1. https://access.redhat.com/security/cve/CVE-2021-27212 2. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27212 This is my evaluation. haven't confirmed it with MITRE as you're already in process. Hope it is true to be the case.
did not hear back from mitre so far. But if we covered this issue in the corect CVE , i will close this bug for now and see i can unmark it adjusrted subject of this bug. added note to CVE page, untagged openldap2.
No problemo, thanks for following up.