RULE(RULE ID:2105220)

Rule General Information
Release Date: 2021-03-26
Rule Name: OpenLDAP LDAP Server BIND Request Denial of Service Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: There exists a vulnerability in the OpenLDAP Lightweight Directory Access Protocol (LDAP) service. The flaw is due to improper handling of specially crafted BIND requests sent to the server which contain overly long CRAM-MD5 credential strings. This can be exploited by an unauthenticated remote attacker to cause an assertion failure, and thus, causing a Denial of Service condition in the affected service. The target server process will terminate as a result of an attack. Consequently, all established connections will be severed and further connections will not be possible until the server is manually restarted.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.