Date:         Fri, 15 Jun 2007 17:27:52 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for openldap on SL3,x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Low: openldap security and bug-fix update
Issue date:	2007-06-11
CVE Names:	CVE-2006-4600

A flaw was found in the way OpenLDAP handled selfwrite access. Users with
selfwrite access were able to modify the distinguished name of any user.
Users with selfwrite access should only be able to modify their own
distinguished name. (CVE-2006-4600)

A memory leak bug was found in OpenLDAP's ldap_start_tls_s() function. An
application using this function could result in an Out Of Memory (OOM)
condition, crashing the application.

SL 3.0.x

   SRPMS:
	openldap-2.0.27-23.src.rpm
   i386:
	openldap-2.0.27-23.i386.rpm
	openldap-clients-2.0.27-23.i386.rpm
	openldap-devel-2.0.27-23.i386.rpm
	openldap-servers-2.0.27-23.i386.rpm
   x86_64:
	openldap-2.0.27-23.i386.rpm
	openldap-2.0.27-23.x86_64.rpm
	openldap-clients-2.0.27-23.x86_64.rpm
	openldap-devel-2.0.27-23.x86_64.rpm
	openldap-servers-2.0.27-23.x86_64.rpm


-Connie Sieh
-Troy Dawson

SciLinux: CVE-2006-4600 openldap SL3,x i386/x86_64

Low: openldap security and bug-fix update

Summary

Date:         Fri, 15 Jun 2007 17:27:52 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for openldap on SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Low: openldap security and bug-fix updateIssue date:	2007-06-11CVE Names:	CVE-2006-4600A flaw was found in the way OpenLDAP handled selfwrite access. Users withselfwrite access were able to modify the distinguished name of any user.Users with selfwrite access should only be able to modify their owndistinguished name. (CVE-2006-4600)A memory leak bug was found in OpenLDAP's ldap_start_tls_s() function. Anapplication using this function could result in an Out Of Memory (OOM)condition, crashing the application.SL 3.0.x   SRPMS:	openldap-2.0.27-23.src.rpm   i386:	openldap-2.0.27-23.i386.rpm	openldap-clients-2.0.27-23.i386.rpm	openldap-devel-2.0.27-23.i386.rpm	openldap-servers-2.0.27-23.i386.rpm   x86_64:	openldap-2.0.27-23.i386.rpm	openldap-2.0.27-23.x86_64.rpm	openldap-clients-2.0.27-23.x86_64.rpm	openldap-devel-2.0.27-23.x86_64.rpm	openldap-servers-2.0.27-23.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News