python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-ldap-debuginfoUpgrade python-ldap | Jan 10, 2024 | Jun 18, 2022 |
| Debian | — | Upgrade python-ldap | Jul 30, 2024 | Jun 18, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python-ldap-help | Nov 3, 2022 | Jun 18, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python-ldap-helpUpgrade python3-ldap | Nov 15, 2022 | Jun 18, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2022 |
| Ubuntu | — | Upgrade python3-ldapUpgrade python-pyldapUpgrade python3-pyldapUpgrade python-ldap | Mar 22, 2023 | Jun 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub