QID 198308

Date Published: 2021-03-31

QID 198308: Ubuntu Security Notification for Ldb Vulnerabilities (USN-4888-1)

It was discovered that ldb, when used with Samba, incorrectly handled certain LDAP attributes.

It was discovered that ldb, when used with Samba, incorrectly handled certain DN strings.

A remote attacker could possibly use this issue to cause the LDAP server to crash, resulting in a denial of service. (CVE-2021-20277)

A remote attacker could use this issue to cause the LDAP server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2020-27840)

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4888-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198308

    Software Advisories
    Advisory ID Software Component Link
    USN-4888-1 16.04 (Xenial) on src libldb1 URL Logo launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.2
    USN-4888-1 18.04 (bionic) on src libldb1 URL Logo launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.2
    USN-4888-1 20.04 (focal) on src libldb2 URL Logo launchpad.net/ubuntu/+source/ldb/2:2.0.10-0ubuntu0.20.04.3
    USN-4888-1 20.10 (groovy) on src libldb2 URL Logo launchpad.net/ubuntu/+source/ldb/2:2.1.4-2ubuntu0.1