Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 12.04 ESM USN-3307-2 Critical: OpenLDAP Denial Of Service Flaw

ubuntu
Calendar Grey July 19, 2017
Dist Ubuntu Esm H88
A security flaw in OpenLDAP found in Ubuntu 12.04 ESM may result in a system crash when exposed to specially designed network packets. Discover additional details.
OpenLDAP could be made to crash if it received specially crafted network traffic.

Summary

OpenLDAP could be made to crash if it received specially crafted

network traffic.

Software Description:

- openldap: OpenLDAP utilities

Details:

USN-3307-1 fixed a vulnerability in OpenLDAP. This update provides the

corresponding update for ubuntu 12.04 ESM.

Original advisory details:

 Karsten Heymann discovered that OpenLDAP incorrectly handled certain

 search requests. A remote attacker could use this issue to cause slapd

 to crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  slapd                           2.4.28-1.1ubuntu4.8

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3307-2

  https://ubuntu.com/security/notices/USN-3307-1

  CVE-2017-9287

Severity
critical
Lowest
Low
Medium
High
Critical

July 19, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here