MGASA-2020-0407 - Updated openldap packages fix a security vulnerability

Publication date: 10 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0407.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-25692

A vulnerability in the handling of normalization with modrdn was discovered in
OpenLDAP. An unauthenticated remote attacker can use this flaw to cause a
denial of service (slapd daemon crash) via a specially crafted packet
(CVE-2020-25692).

Also, the PID file path in the systemd service was fixed to use /run as the$
parent, rather than /var/run, eliminating warning messages in the logs.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26768
- https://bugs.openldap.org/show_bug.cgi?id=9370
- https://www.debian.org/security/2020/dsa-4782
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25692

SRPMS:
- 7/core/openldap-2.4.50-1.2.mga7