Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 15.04, 14.04, 12.04 LTS: Critical USN-2742-1 OpenLDAP DoS

ubuntu
Calendar Grey September 16, 2015
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
Several security issues were fixed in OpenLDAP.

Summary

Several security issues were fixed in OpenLDAP.

Software Description:

- openldap: OpenLDAP utilities

Details:

Denis Andzakovic discovered that OpenLDAP incorrectly handled certain BER

data. A remote attacker could possibly use this issue to cause OpenLDAP to

crash, resulting in a denial of service. (CVE-2015-6908)

Dietrich Clauss discovered that the OpenLDAP package incorrectly shipped

with a potentially unsafe default access control configuration. Depending

on how the database is configure, this may allow users to impersonate

others by modifying attributes such as their Unix user and group numbers.

(CVE-2014-9713)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  slapd                           2.4.31-1+nmu2ubuntu12.3

Ubuntu 14.04 LTS:
  slapd                           2.4.31-1+nmu2ubuntu8.2

Ubuntu 12.04 LTS:
  slapd                           2.4.28-1.1ubuntu4.6

In general, a standard system update will make all the necessary changes.

For existing installations, access rules that begin with "to *" need to be
manually adjusted to remove any instances of "by self write".

References

https://ubuntu.com/security/notices/USN-2742-1

CVE-2014-9713, CVE-2015-6908

Severity
critical
Lowest
Low
Medium
High
Critical

September 16, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.