security advisoryDoSopenldap
Important: openldap security and enhancement update. Date: Tue, 13 Nov 2007 17:05:13 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for openldap on SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: openldap security and enhancement update Issue date: 2007-11-08 CVE Names: CVE-2007-5707 A flaw was found in the way OpenLDAP's slapd daemon handled malformed objectClasses LDAP attributes. A local or remote attacker could create an LDAP request which could cause a denial of service by crashing slapd. (CVE-2007-5707) In addition, the following feature was added: * OpenLDAP client tools now have new option to configure their bind timeout SL 5.x SRPMS: openldap-2.3.27-8.el5_1.1.src.rpm i386: openldap-2.3.27-8.el5.1.i386.rpm openldap-clients-2.3.27-8.el5.1.i386.rpm openldap-devel-2.3.27-8.el5.1.i386.rpm openldap-servers-2.3.27-8.el5.1.i386.rpm openldap-servers-sql-2.3.27-8.el5.1.i386.rpm x86_64: openldap-2.3.27-8.el5.1.i386.rpm openldap-2.3.27-8.el5.1.x86_64.rpm openldap-clients-2.3.27-8.el5.1.x86_64.rpm openldap-devel-2.3.27-8.el5.1.i386.rpm openldap-devel-2.3.27-8.el5.1.x86_64.rpm openldap-servers-2.3.27-8.el5.1.x86_64.rpm openldap-servers-sql-2.3.27-8.el5.1.x86_64.rpm -Connie Sieh -Troy Dawson . A security patch for OpenLDAP addresses a denial-of-service vulnerability on Scientific Linux platforms, reinforcing system defenses.. openldap security update, Scientific Linux advisory, DoS fix. . LinuxSecurity.com Team
Nov 13, 2007
Scientific Linux