Lucene search

K
redhatRedHatRHSA-2008:0110
HistoryFeb 21, 2008 - 12:00 a.m.

(RHSA-2008:0110) Moderate: openldap security update

2008-02-2100:00:00
access.redhat.com
17

EPSS

0.007

Percentile

80.9%

OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.

These updated openldap packages fix a flaw in the way the OpenLDAP slapd
daemon handled modify and modrdn requests with NOOP control on objects
stored in a Berkeley DB (BDB) storage backend. An authenticated attacker
with permission to perform modify or modrdn operations on such LDAP objects
could cause slapd to crash. (CVE-2007-6698, CVE-2008-0658)

Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.