CVE-2021-46823

Publication date 18 June 2022

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

Status

Package Ubuntu Release Status
python-ldap 22.04 LTS jammy
Fixed 3.2.0-4ubuntu7.1
21.10 impish
Fixed 3.2.0-4ubuntu5.1
20.04 LTS focal
Fixed 3.2.0-4ubuntu2.1
18.04 LTS bionic
Fixed 3.0.0-1ubuntu0.2

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
python-ldap

Severity score breakdown

Parameter Value
Base score 6.5 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H