Lucene search

K
centosCentOS ProjectCESA-2007:1038
HistoryNov 15, 2007 - 7:22 p.m.

compat, openldap security update

2007-11-1519:22:48
CentOS Project
lists.centos.org
46

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.038

Percentile

92.0%

CentOS Errata and Security Advisory CESA-2007:1038

OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP’s slapd daemon handled malformed
objectClasses LDAP attributes. An authenticated local or remote attacker
could create an LDAP request which could cause a denial of service by
crashing slapd. (CVE-2007-5707)

In addition, the following feature was added:

  • OpenLDAP client tools now have new option to configure their bind timeout.

All users are advised to upgrade to these updated openldap packages, which
contain a backported patch to correct this issue and provide this security
enhancement.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-November/076594.html
https://lists.centos.org/pipermail/centos-announce/2007-November/076611.html

Affected packages:
compat-openldap
openldap
openldap-clients
openldap-devel
openldap-servers
openldap-servers-sql

Upstream details at:
https://access.redhat.com/errata/RHSA-2007:1038

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.038

Percentile

92.0%