[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2010:0543-01 -- Redhat openldap

ID: oval:org.secpod.oval:def:500361Date: (C)2012-01-31   (M)2024-02-19
Class: PATCHFamily: unix




OpenLDAP is an open source suite of LDAP applications and development tools. An uninitialized pointer use flaw was discovered in the way the slapd daemon handled modify relative distinguished name requests. An authenticated user with privileges to perform modrdn operations could use this flaw to crash the slapd daemon via specially-crafted modrdn requests. Red Hat would like to thank CERT-FI for responsibly reporting the CVE-2010-0211 flaw, who credit Ilkka Mattila and Tuomas Salomki for the discovery of the issue. A flaw was found in the way OpenLDAP handled NUL characters in the CommonName field of X.509 certificates. An attacker able to get a carefully-crafted certificate signed by a trusted Certificate Authority could trick applications using OpenLDAP libraries into accepting it by mistake, allowing the attacker to perform a man-in-the-middle attack. Users of OpenLDAP should upgrade to these updated packages, which contain backported patches to resolve these issues. After installing this update, the OpenLDAP daemons will be restarted automatically.

Platform:
Red Hat Enterprise Linux 4
Product:
openldap
Reference:
RHSA-2010:0543-01
CVE-2009-3767
CVE-2010-0211
CVE    2
CVE-2009-3767
CVE-2010-0211
CPE    1
cpe:/o:redhat:enterprise_linux:4

© SecPod Technologies