OpenPKG Security Advisory
OpenPKG-SA-2006.008
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.008
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.008
Advisory Published: 2010-02-09 16:12 UTC
Issue Id (internal): OpenPKG-SI-20060522.01
Issue First Created: 2006-05-22
Issue Last Modified: 2006-11-28
Issue Revision: 05
Subject Name: OpenLDAP
Subject Summary: Lightweight Directory Access Protocol (LDAP) Toolkit
Subject Home: http://www.openldap.org/
Subject Versions: * <= 2.3.21
Vulnerability Id: none
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector:
Attack Impact: denial of service
Description:
According to a Secunia security advisory [0], a weakness exists in
OpenLDAP [1] which is caused due to a boundary error in slurpd(8)
within the handling of the status file. This can be exploited to cause
a stack-based buffer overflow via an overly long hostname read from
the status file. The weakness has been reported to be in OpenLDAP
version 2.3.21 and earlier.
References:
[0] http://secunia.com/advisories/20126
[1] http://www.openldap.org/
Primary Package Name: openldap
Primary Package Home: http://openpkg.org/go/package/openldap
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.3-SOLID openldap-2.2.23-2.3.1
OpenPKG Community 2.4-SOLID openldap-2.2.27-2.4.0
OpenPKG Community 2.5-SOLID openldap-2.3.11-2.5.0
OpenPKG Community CURRENT openldap-2.3.21-20060510
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.3-SOLID openldap-2.2.23-2.3.2
OpenPKG Community 2.4-SOLID openldap-2.2.27-2.4.1
OpenPKG Community 2.5-SOLID openldap-2.3.11-2.5.1
OpenPKG Community CURRENT openldap-2.3.22-20060517