QID 352270
Date Published: 2021-04-26
QID 352270: Amazon Linux Security Advisory for libldb: ALAS2-2021-1628
<DIV ID="issue_overview">
A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability. (CVE-2021-20277 )
</DIV>
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
Solution
Please refer to Amazon advisory: ALAS-2021-1628 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS-2021-1628 -
alas.aws.amazon.com/AL2/ALAS-2021-1628.html
CVEs related to QID 352270
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS-2021-1628 | Amazon Linux 2 |
|