Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Scientific Linux: CVE-2007-5707 Moderate: OpenLDAP Denial of Service

Scientific Large Esm H446
Moderate: openldap security and enhancement update
Date:         Thu, 15 Nov 2007 14:11:22 -0600
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for openldap on SL4.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis:	Moderate: openldap security and enhancement update
Issue date:	2007-11-15
CVE Names:	CVE-2007-5707

A flaw was found in the way OpenLDAP's slapd daemon handled malformed
objectClasses LDAP attributes.  An authenticated local or remote attacker
could create an LDAP request which could cause a denial of service by
crashing slapd. (CVE-2007-5707)

SL 4.x

   SRPMS:
openldap-2.2.13-8.1.src.rpm
   i386:
compat-openldap-2.1.30-8.1.i386.rpm
openldap-2.2.13-8.1.i386.rpm
openldap-clients-2.2.13-8.1.i386.rpm
openldap-devel-2.2.13-8.1.i386.rpm
openldap-servers-2.2.13-8.1.i386.rpm
openldap-servers-sql-2.2.13-8.1.i386.rpm
   x86_64:
compat-openldap-2.1.30-8.1.i386.rpm
compat-openldap-2.1.30-8.1.x86_64.rpm
openldap-2.2.13-8.1.i386.rpm
openldap-2.2.13-8.1.x86_64.rpm
openldap-clients-2.2.13-8.1.x86_64.rpm
openldap-devel-2.2.13-8.1.x86_64.rpm
openldap-servers-2.2.13-8.1.x86_64.rpm
openldap-servers-sql-2.2.13-8.1.x86_64.rpm

-Connie Sieh
-Troy Dawson