Denial of Service in python-ldap
Moderate severity
GitHub Reviewed
Published
Jun 19, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Description
Published by the National Vulnerability Database
Jun 18, 2022
Published to the GitHub Advisory Database
Jun 19, 2022
Reviewed
Jun 20, 2022
Last updated
Aug 17, 2023
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
References