Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 7 DLA-972-1 Critical: Openldap Double-Free Server Crash Risk

debian lts
Calendar Grey June 1, 2017
Dist Debian Esm H88
Elevate openldap on Debian 7 to address a dual-release problem leading to server failures. See advisory DLA-972-1 for specifics.
It was discovered that there was a double-free vulnerability in the "openldap" LDAP server

Summary

A user with access to search the directory could crash slapd by issuing
a search requesting a "Paged Results" value set to zero.

For Debian 7 "Wheezy", this issue has been fixed in openldap version
2.4.31-2+deb7u3.

We recommend that you upgrade your openldap packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
critical
Lowest
Low
Medium
High
Critical

Package: openldap
Version: 2.4.31-2+deb7u3
CVE ID: CVE-2017-9287
Debian Bug: #863563

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here