Rapid7 Vulnerability & Exploit Database

RHSA-2010:0542: openldap security update

Back to Search

RHSA-2010:0542: openldap security update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
07/28/2010
Created
07/25/2018
Added
07/28/2010
Modified
07/04/2017

Description

OpenLDAP is an open source suite of LDAP (Lightweight Directory AccessProtocol) applications and development tools.Multiple flaws were discovered in the way the slapd daemon handled modifyrelative distinguished name (modrdn) requests. An authenticated user withprivileges to perform modrdn operations could use these flaws to crash theslapd daemon via specially-crafted modrdn requests. (CVE-2010-0211,CVE-2010-0212)Red Hat would like to thank CERT-FI for responsibly reporting these flaws,who credit Ilkka Mattila and Tuomas Salomäki for the discovery of theissues.Users of OpenLDAP should upgrade to these updated packages, which containa backported patch to correct these issues. After installing this update,the OpenLDAP daemons will be restarted automatically.

Solution(s)

  • redhat-upgrade-compat-openldap
  • redhat-upgrade-openldap
  • redhat-upgrade-openldap-clients
  • redhat-upgrade-openldap-devel
  • redhat-upgrade-openldap-servers
  • redhat-upgrade-openldap-servers-overlays
  • redhat-upgrade-openldap-servers-sql

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;