CVE-2020-25709: Apple Mac OS X

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

Affected products

  • Apple Mac OS X: from 10.14.0, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.7 (fixed in 10.15.7); version 10.14.6 only; version 10.15.7 only
  • Apple macOS: from 11.0, before 11.0.1 (fixed in 11.0.1)
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Openldap Openldap: before 2.4.56 (fixed in 2.4.56)
  • Red Hat JBoss Core Services: affected versions not specified

Published 2021-05-18. Last modified 2026-06-17.