QID 352265

Date Published: 2021-04-26

QID 352265: Amazon Linux Security Advisory for libldb: ALAS-2021-1494

<DIV ID="issue_overview">
A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability. (CVE-2021-20277 )
</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Medium - 5.6 severity.
  • CVSS V2 rated as Low - 1.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2021-1494 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352265

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1494 Amazon Linux URL Logo alas.aws.amazon.com/ALAS-2021-1494.html