Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2021:0473-1 Critical: Openldap2 Security Vulnerability Resolution

suse
Calendar Grey January 27, 2016
Dist Suse Esm H88
Discover the essential security patch from SUSE for openldap2, which addresses critical vulnerabilities. Update your systems immediately to ensure protection.
An update that fixes two vulnerabilities is now available

Summary

This update fixes the following security issues: - CVE-2015-6908: The ber_get_next function allowed remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. (bsc#945582) - CVE-2015-4000: Fix weak Diffie-Hellman size vulnerability. (bsc#937766) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-openldap2-20160114-12372=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.3 (x86_64): openldap2-devel-2.4.26-0.17.23.1

References

#937766 #945582

Cross- CVE-2015-4000 CVE-2015-6908

Affected Products:

SUSE Studio Onsite 1.3

https://www.suse.com/security/cve/CVE-2015-4000.html

https://www.suse.com/security/cve/CVE-2015-6908.html

https://bugzilla.suse.com/show_bug.cgi?id=937766

https://bugzilla.suse.com/show_bug.cgi?id=945582

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0262-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here