All errata/p8/ALT-PU-2017-2179-1
ALT-PU-2017-2179-1

Package update openldap in branch p8

Version2.4.45-alt0.M80P.1
Published2017-09-11
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2015-6908
MEDIUM5.0

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

Published: 2015-09-11Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
References

Closed bugs (1)

ldap.conf manpage belongs to clients, not servers