You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa openldap

Sigurnosni nedostaci programskog paketa openldap

==========================================================================
Ubuntu Security Notice USN-4634-2
November 23, 2020

openldap vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 ESM
– Ubuntu 12.04 ESM

Summary:

OpenLDAP could be made to crash if it received specially crafted network
traffic.

Software Description:
– openldap: Lightweight Directory Access Protocol

Details:

USN-4634-1 fixed several vulnerabilities in OpenLDAP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that OpenLDAP incorrectly handled certain malformed
inputs. A remote attacker could possibly use this issue to cause OpenLDAP
to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
slapd 2.4.31-1+nmu2ubuntu8.5+esm4

Ubuntu 12.04 ESM:
slapd 2.4.28-1.1ubuntu4.12

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4634-2
https://usn.ubuntu.com/4634-1
CVE-2020-25709, CVE-2020-25710
—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl+7s+gACgkQRbznW4QL
H2k5dw/9E4HsneIciT08tMnn+ePI1nAN0WoCPm5VulniXE3UN/u1qMJKVFpJLoln
7t/LaT7Q7aM7ca6ThZ3q6yxmJ9X0WnIMJv73slsmBfeW4KtnZUtfAQ97U2PvO9hm
FhmAVmfLquXYMxmebr26yyMV/gfJcgZnfCAc37gY+f27Yv+ht4yAyLE6cRoh9IH5
mwBsfQabtczWgXPNVKaypBOtize82ybMeya3AMvrnrMdgGtZEn9wkL80uCEnmyQL
jOqllp8k4uPQr0XpBD0PYnTZwm897isBXgnMLPIaWu8rcJ34kdwvtkPKSrAF3GP9
NVrQQ0/0VHhPDPbNs2ekfPavevJoijtwXaTkXaALRCaUzcJpkM17k4v7E1NS6ZcE
ca0PcLt6pYYbGbqDCBujHRJbJ2d9/9NlEJ4NCi7mxKPTXL5M30fiRzsvJemNthie
5psOiNWJC+3RXXzb+NvTNhwYLBndURH/5wDIfUpKcjB0vKKMqCmMV/g7JkHURZH7
7/oz1CaVSnH6T1p7mNO2AGHr3AChTxw89BjxnP2JtYv/jnIOCaNfTVN0wqPPtPfK
GoEO+LNMD/syhLfWfLuVJFOzxd7w+ZDmG02YcIchMU4YREAe8ez/V4MO0uKWMtAq
bo9DsWssGXUR9IZgXkrCpp8SgJeBKQ1/cQBa4MeTbfm7S88ydk4=
=LKtb
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa blueman

Otkriven je sigurnosni nedostatak u programskom paketu blueman za operacijski sustav openSUSE. Otkriveni nedostatak potencijalnim napadačima omogućuje stjecanje uvećanih ovlasti....

Close