[ MDVSA-2008:058 ] - Updated openldap packages fix multiple

Mandrivan turvallisuustiedotteiden tuoreimmat

[ MDVSA-2008:058 ] - Updated openldap packages fix multiple

Uusi viestiKirjoittaja dude67 » 05 Maalis 2008, 22:54

Updated openldap packages fix multiple vulnerabilities

A vulnerability was found in slapo-pcache in slapd of OpenLDAP prior
to 2.3.39 when running as a proxy-caching server. It would allocate
memory using a malloc variant rather than calloc, which prevented
an array from being properly initialized and could possibly allow
attackers to cause a denial of service (CVE-2007-5708).

Two vulnerabilities were found in how slapd handled modify (prior
to 2.3.26) and modrdn (prior to 2.3.29) requests with NOOP control
on objects stored in the BDB backend. An authenticated user with
permission to perform modify (CVE-2007-6698) or modrdn (CVE-2008-0658)
operations could cause slapd to crash.

The updated packages have been patched to correct these issues.
Kuva
1. Mageia-1 KDE4 x86_64 (& Win7 Pro) | desktop
2. Mageia-2 KDE4 (& Win7 Home Premium) | laptop Acer 7530
3. Mageia-1 KDE4 (& Win7 Starter) | Samsung NC-10 miniläppäri
4. Mageia-1 KDE4 | serverinä toimiva desktop
Luotettavaa Linux käyttöä jo Mandriva 2006.0:sta lähtien :)
Avatar
dude67
Site Admin
 
Viestit: 2256
Liittynyt: 27 Syys 2007, 16:58
Paikkakunta: Espoo

Paluu Mandrivan turvallisuustiedotteet

Paikallaolijat

Käyttäjiä lukemassa tätä aluetta: Ei rekisteröityneitä käyttäjiä ja 51 vierailijaa

cron