QID 354630
Date Published: 2023-01-02
QID 354630: Amazon Linux Security Advisory for openldap : AL2012-2022-362
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-29155:
2081935: CVE-2022-29155 openldap: OpenLDAP SQL injection
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 354630
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2022-362 | Amazon Linux Bare Metal |
|