CVE-2020-15719
ADVISORY - debianSummary
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
- openldap (unimportant; bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965184) https://bugs.openldap.org/show_bug.cgi?id=9266 https://bugzilla.redhat.com/show_bug.cgi?id=1740070 RedHat/CentOS applied patch: https://git.centos.org/rpms/openldap/raw/67459960064be9d226d57c5f82aaba0929876813/f/SOURCES/openldap-tlso-dont-check-cn-when-bad-san.patch OpenLDAP upstream did dispute the issue as beeing valid, as the current libldap behaviour does conform with RFC4513. RFC6125 does not superseed the rules for verifying service identity provided in specifications for existing application protocols published prior to RFC6125, like RFC4513 for LDAP.
EPSS Score: 0.00371 (0.580)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Certificate Validation
ADVISORY - redhat
Improper Validation of Certificate with Host Mismatch
Debian
CREATED
UPDATED
ADVISORY IDCVE-2020-15719
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowPackage | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/openldap | deb | debian | 12 | >=2.5.13+dfsg-5 | Not yet available |
debian/openldap | deb | debian | 13 | >=2.6.9+dfsg-2 | Not yet available |
debian/openldap | deb | debian | 11 | >=2.4.57+dfsg-3+deb11u1 | Not yet available |
debian/openldap | deb | debian | unstable | >=2.6.9+dfsg-2 | Not yet available |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2020-15719
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.2mediumUbuntu
CREATED
UPDATED
ADVISORY IDCVE-2020-15719
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
4.2lowBitnami
CREATED
UPDATED
ADVISORY ID
BIT-2020-15719
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-openldap-2020-15719
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
4.2mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2020-15719
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)