{"id":"CVE-2020-36228","details":"An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.","aliases":["BIT-openldap-2020-36228"],"modified":"2026-04-02T06:08:30.170371Z","published":"2021-01-26T18:15:57.223Z","related":["MGASA-2021-0105","SUSE-SU-2021:0692-1","SUSE-SU-2021:0693-1","SUSE-SU-2021:0723-1","SUSE-SU-2021:14700-1","openSUSE-SU-2021:0408-1"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4845"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/May/64"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/May/65"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/02/msg00005.html"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT212530"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2021/May/70"},{"type":"ADVISORY","url":"https://git.openldap.org/openldap/openldap/-/tags/OPENLDAP_REL_ENG_2_4_57"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210226-0002/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT212529"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT212531"},{"type":"REPORT","url":"https://bugs.openldap.org/show_bug.cgi?id=9427"},{"type":"FIX","url":"https://git.openldap.org/openldap/openldap/-/commit/91dccd25c347733b365adc74cb07d074512ed5ad"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openldap/openldap","events":[{"introduced":"0"},{"fixed":"3b03d6bea27f29b7f7f91b3d5488fbd6e69b6c29"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"2.4.57"}]}}],"versions":["ACLCHECK_0","AUTOCONF_2_57","FreeBSD_3_3","GTK_TOOL_0_0","LDAP_3_3+prerelease","LDBM_POST_GIANT_RWLOCK","LDBM_PRE_GIANT_RWLOCK","LMDB_0.9.15","LMDB_0.9.16","LMDB_0.9.17","LMDB_0.9.18","LMDB_0.9.19","LMDB_0.9.20","LMDB_0.9.21","LMDB_0.9.22","LMDB_0.9.23","LMDB_0.9.24","LMDB_0.9.25","LMDB_0.9.26","LMDB_0.9.27","LMDB_0.9.28","LMDB_0.9.29","LMDB_0.9.30","LMDB_0.9.31","LMDB_0.9.32","LMDB_0.9.33","LMDB_0.9.34","LMDB_0.9.35","LOCKER_IDS","MIGRATION_CVS2GIT","NO_SLAP_OP_BLOCKS","OPENDLAP_REL_ENG_2_2_MP","OPENLDAP_AC_BP","OPENLDAP_REL_ENG_1_0_0","OPENLDAP_REL_ENG_1_0_1","OPENLDAP_REL_ENG_1_0_2","OPENLDAP_REL_ENG_1_0_3","OPENLDAP_REL_ENG_1_1_0","OPENLDAP_REL_ENG_1_1_1","OPENLDAP_REL_ENG_1_1_2","OPENLDAP_REL_ENG_1_1_3","OPENLDAP_REL_ENG_1_1_4","OPENLDAP_REL_ENG_1_1_ALPHA","OPENLDAP_REL_ENG_1_1_ALPHA2","OPENLDAP_REL_ENG_1_1_ALPHA3","OPENLDAP_REL_ENG_1_1_BETA","OPENLDAP_REL_ENG_1_2_0","OPENLDAP_REL_ENG_1_2_1","OPENLDAP_REL_ENG_1_2_10","OPENLDAP_REL_ENG_1_2_11","OPENLDAP_REL_ENG_1_2_12","OPENLDAP_REL_ENG_1_2_13","OPENLDAP_REL_ENG_1_2_2","OPENLDAP_REL_ENG_1_2_3","OPENLDAP_REL_ENG_1_2_4","OPENLDAP_REL_ENG_1_2_5","OPENLDAP_REL_ENG_1_2_6","OPENLDAP_REL_ENG_1_2_7","OPENLDAP_REL_ENG_1_2_8","OPENLDAP_REL_ENG_1_2_9","OPENLDAP_REL_ENG_1_2_BETA","OPENLDAP_REL_ENG_1_2_BETA2","OPENLDAP_REL_ENG_2_0_0","OPENLDAP_REL_ENG_2_0_1","OPENLDAP_REL_ENG_2_0_10","OPENLDAP_REL_ENG_2_0_11","OPENLDAP_REL_ENG_2_0_12","OPENLDAP_REL_ENG_2_0_13","OPENLDAP_REL_ENG_2_0_14","OPENLDAP_REL_ENG_2_0_15","OPENLDAP_REL_ENG_2_0_16","OPENLDAP_REL_ENG_2_0_17","OPENLDAP_REL_ENG_2_0_18","OPENLDAP_REL_ENG_2_0_19","OPENLDAP_REL_ENG_2_0_2","OPENLDAP_REL_ENG_2_0_20","OPENLDAP_REL_ENG_2_0_21","OPENLDAP_REL_ENG_2_0_22","OPENLDAP_REL_ENG_2_0_23","OPENLDAP_REL_ENG_2_0_24","OPENLDAP_REL_ENG_2_0_25","OPENLDAP_REL_ENG_2_0_26","OPENLDAP_REL_ENG_2_0_27","OPENLDAP_REL_ENG_2_0_3","OPENLDAP_REL_ENG_2_0_4","OPENLDAP_REL_ENG_2_0_5","OPENLDAP_REL_ENG_2_0_6","OPENLDAP_REL_ENG_2_0_7","OPENLDAP_REL_ENG_2_0_8","OPENLDAP_REL_ENG_2_0_9","OPENLDAP_REL_ENG_2_0_ALPHA","OPENLDAP_REL_ENG_2_0_ALPHA2","OPENLDAP_REL_ENG_2_0_ALPHA3","OPENLDAP_REL_ENG_2_0_ALPHA4","OPENLDAP_REL_ENG_2_0_BETA","OPENLDAP_REL_ENG_2_0_GAMMA","OPENLDAP_REL_ENG_2_1_10","OPENLDAP_REL_ENG_2_1_11","OPENLDAP_REL_ENG_2_1_12","OPENLDAP_REL_ENG_2_1_13","OPENLDAP_REL_ENG_2_1_14","OPENLDAP_REL_ENG_2_1_15","OPENLDAP_REL_ENG_2_1_16","OPENLDAP_REL_ENG_2_1_17","OPENLDAP_REL_ENG_2_1_18","OPENLDAP_REL_ENG_2_1_19","OPENLDAP_REL_ENG_2_1_2","OPENLDAP_REL_ENG_2_1_20","OPENLDAP_REL_ENG_2_1_21","OPENLDAP_REL_ENG_2_1_22","OPENLDAP_REL_ENG_2_1_23","OPENLDAP_REL_ENG_2_1_24","OPENLDAP_REL_ENG_2_1_25","OPENLDAP_REL_ENG_2_1_26","OPENLDAP_REL_ENG_2_1_27","OPENLDAP_REL_ENG_2_1_28","OPENLDAP_REL_ENG_2_1_29","OPENLDAP_REL_ENG_2_1_3","OPENLDAP_REL_ENG_2_1_30","OPENLDAP_REL_ENG_2_1_4","OPENLDAP_REL_ENG_2_1_5","OPENLDAP_REL_ENG_2_1_6","OPENLDAP_REL_ENG_2_1_7","OPENLDAP_REL_ENG_2_1_8","OPENLDAP_REL_ENG_2_1_9","OPENLDAP_REL_ENG_2_1_ALPHA0","OPENLDAP_REL_ENG_2_1_BETA1","OPENLDAP_REL_ENG_2_1_BP","OPENLDAP_REL_ENG_2_1_MP","OPENLDAP_REL_ENG_2_2_0ALPHA","OPENLDAP_REL_ENG_2_2_10","OPENLDAP_REL_ENG_2_2_11","OPENLDAP_REL_ENG_2_2_12","OPENLDAP_REL_ENG_2_2_13","OPENLDAP_REL_ENG_2_2_14","OPENLDAP_REL_ENG_2_2_15","OPENLDAP_REL_ENG_2_2_16","OPENLDAP_REL_ENG_2_2_17","OPENLDAP_REL_ENG_2_2_18","OPENLDAP_REL_ENG_2_2_19","OPENLDAP_REL_ENG_2_2_1BETA","OPENLDAP_REL_ENG_2_2_20","OPENLDAP_REL_ENG_2_2_21","OPENLDAP_REL_ENG_2_2_22","OPENLDAP_REL_ENG_2_2_23","OPENLDAP_REL_ENG_2_2_24","OPENLDAP_REL_ENG_2_2_25","OPENLDAP_REL_ENG_2_2_26","OPENLDAP_REL_ENG_2_2_27","OPENLDAP_REL_ENG_2_2_28","OPENLDAP_REL_ENG_2_2_29","OPENLDAP_REL_ENG_2_2_2BETA","OPENLDAP_REL_ENG_2_2_30","OPENLDAP_REL_ENG_2_2_3BETA","OPENLDAP_REL_ENG_2_2_4","OPENLDAP_REL_ENG_2_2_5","OPENLDAP_REL_ENG_2_2_6","OPENLDAP_REL_ENG_2_2_7","OPENLDAP_REL_ENG_2_2_8","OPENLDAP_REL_ENG_2_2_9","OPENLDAP_REL_ENG_2_2_BP","OPENLDAP_REL_ENG_2_2_MP","OPENLDAP_REL_ENG_2_3_0ALPHA","OPENLDAP_REL_ENG_2_3_10","OPENLDAP_REL_ENG_2_3_11","OPENLDAP_REL_ENG_2_3_12","OPENLDAP_REL_ENG_2_3_13","OPENLDAP_REL_ENG_2_3_14","OPENLDAP_REL_ENG_2_3_15","OPENLDAP_REL_ENG_2_3_16","OPENLDAP_REL_ENG_2_3_17","OPENLDAP_REL_ENG_2_3_18","OPENLDAP_REL_ENG_2_3_19","OPENLDAP_REL_ENG_2_3_1ALPHA","OPENLDAP_REL_ENG_2_3_20","OPENLDAP_REL_ENG_2_3_21","OPENLDAP_REL_ENG_2_3_22","OPENLDAP_REL_ENG_2_3_23","OPENLDAP_REL_ENG_2_3_24","OPENLDAP_REL_ENG_2_3_25","OPENLDAP_REL_ENG_2_3_26","OPENLDAP_REL_ENG_2_3_27","OPENLDAP_REL_ENG_2_3_28","OPENLDAP_REL_ENG_2_3_29","OPENLDAP_REL_ENG_2_3_2BETA","OPENLDAP_REL_ENG_2_3_30","OPENLDAP_REL_ENG_2_3_31","OPENLDAP_REL_ENG_2_3_32","OPENLDAP_REL_ENG_2_3_33","OPENLDAP_REL_ENG_2_3_34","OPENLDAP_REL_ENG_2_3_35","OPENLDAP_REL_ENG_2_3_36","OPENLDAP_REL_ENG_2_3_37","OPENLDAP_REL_ENG_2_3_38","OPENLDAP_REL_ENG_2_3_39","OPENLDAP_REL_ENG_2_3_3BETA","OPENLDAP_REL_ENG_2_3_4","OPENLDAP_REL_ENG_2_3_40","OPENLDAP_REL_ENG_2_3_41","OPENLDAP_REL_ENG_2_3_42","OPENLDAP_REL_ENG_2_3_43","OPENLDAP_REL_ENG_2_3_5","OPENLDAP_REL_ENG_2_3_6","OPENLDAP_REL_ENG_2_3_7","OPENLDAP_REL_ENG_2_3_8","OPENLDAP_REL_ENG_2_3_9","OPENLDAP_REL_ENG_2_3_BP","OPENLDAP_REL_ENG_2_3_MP","OPENLDAP_REL_ENG_2_4_0ALPHA","OPENLDAP_REL_ENG_2_4_10","OPENLDAP_REL_ENG_2_4_11","OPENLDAP_REL_ENG_2_4_12","OPENLDAP_REL_ENG_2_4_13","OPENLDAP_REL_ENG_2_4_14","OPENLDAP_REL_ENG_2_4_15","OPENLDAP_REL_ENG_2_4_16","OPENLDAP_REL_ENG_2_4_17","OPENLDAP_REL_ENG_2_4_18","OPENLDAP_REL_ENG_2_4_19","OPENLDAP_REL_ENG_2_4_1ALPHA","OPENLDAP_REL_ENG_2_4_20","OPENLDAP_REL_ENG_2_4_21","OPENLDAP_REL_ENG_2_4_22","OPENLDAP_REL_ENG_2_4_23","OPENLDAP_REL_ENG_2_4_24","OPENLDAP_REL_ENG_2_4_25","OPENLDAP_REL_ENG_2_4_26","OPENLDAP_REL_ENG_2_4_27","OPENLDAP_REL_ENG_2_4_28","OPENLDAP_REL_ENG_2_4_29","OPENLDAP_REL_ENG_2_4_2ALPHA","OPENLDAP_REL_ENG_2_4_30","OPENLDAP_REL_ENG_2_4_31","OPENLDAP_REL_ENG_2_4_32","OPENLDAP_REL_ENG_2_4_33","OPENLDAP_REL_ENG_2_4_34","OPENLDAP_REL_ENG_2_4_35","OPENLDAP_REL_ENG_2_4_36","OPENLDAP_REL_ENG_2_4_37","OPENLDAP_REL_ENG_2_4_38","OPENLDAP_REL_ENG_2_4_39","OPENLDAP_REL_ENG_2_4_3ALPHA","OPENLDAP_REL_ENG_2_4_40","OPENLDAP_REL_ENG_2_4_41","OPENLDAP_REL_ENG_2_4_42","OPENLDAP_REL_ENG_2_4_43","OPENLDAP_REL_ENG_2_4_44","OPENLDAP_REL_ENG_2_4_45","OPENLDAP_REL_ENG_2_4_46","OPENLDAP_REL_ENG_2_4_47","OPENLDAP_REL_ENG_2_4_48","OPENLDAP_REL_ENG_2_4_49","OPENLDAP_REL_ENG_2_4_4ALPHA","OPENLDAP_REL_ENG_2_4_50","OPENLDAP_REL_ENG_2_4_51","OPENLDAP_REL_ENG_2_4_52","OPENLDAP_REL_ENG_2_4_53","OPENLDAP_REL_ENG_2_4_54","OPENLDAP_REL_ENG_2_4_55","OPENLDAP_REL_ENG_2_4_56","OPENLDAP_REL_ENG_2_4_5BETA","OPENLDAP_REL_ENG_2_4_6","OPENLDAP_REL_ENG_2_4_7","OPENLDAP_REL_ENG_2_4_8","OPENLDAP_REL_ENG_2_4_9","OPENLDAP_REL_ENG_2_4_BP","OPENLDAP_REL_ENG_2_4_MP","OPENLDAP_REL_ENG_2_5_0ALPHA","OPENLDAP_REL_ENG_2_5_10","OPENLDAP_REL_ENG_2_5_11","OPENLDAP_REL_ENG_2_5_12","OPENLDAP_REL_ENG_2_5_13","OPENLDAP_REL_ENG_2_5_14","OPENLDAP_REL_ENG_2_5_15","OPENLDAP_REL_ENG_2_5_16","OPENLDAP_REL_ENG_2_5_17","OPENLDAP_REL_ENG_2_5_18","OPENLDAP_REL_ENG_2_5_19","OPENLDAP_REL_ENG_2_5_1ALPHA","OPENLDAP_REL_ENG_2_5_20","OPENLDAP_REL_ENG_2_5_2BETA","OPENLDAP_REL_ENG_2_5_3BETA","OPENLDAP_REL_ENG_2_5_4","OPENLDAP_REL_ENG_2_5_5","OPENLDAP_REL_ENG_2_5_6","OPENLDAP_REL_ENG_2_5_7","OPENLDAP_REL_ENG_2_5_8","OPENLDAP_REL_ENG_2_5_9","OPENLDAP_REL_ENG_2_6_0","OPENLDAP_REL_ENG_2_6_1","OPENLDAP_REL_ENG_2_6_10","OPENLDAP_REL_ENG_2_6_11","OPENLDAP_REL_ENG_2_6_12","OPENLDAP_REL_ENG_2_6_13","OPENLDAP_REL_ENG_2_6_2","OPENLDAP_REL_ENG_2_6_3","OPENLDAP_REL_ENG_2_6_4","OPENLDAP_REL_ENG_2_6_5","OPENLDAP_REL_ENG_2_6_6","OPENLDAP_REL_ENG_2_6_7","OPENLDAP_REL_ENG_2_6_8","OPENLDAP_REL_ENG_2_6_9","OPENLDAP_REL_ENG_2_BP","OPENLDAP_REL_ENG_2_MP","OPENLDAP_SLAPD_BACK_LDAP","PHP3_TOOL_0_0","TWEB_OL_BASE","UCDATA_2_4","UMICH_LDAP_3_3","URE_0_5","UTBM_0_2"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"10.0"}]},{"events":[{"introduced":"11.1"},{"fixed":"11.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36228.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}