All errata/c7/ALT-PU-2017-2187-1
ALT-PU-2017-2187-1

Package update openldap in branch c7

Version2.4.45-alt0.M70C.1
Published2017-09-12
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2015-6908
MEDIUM5.0

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

Published: 2015-09-11Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
References