Mandriva Linux Security Advisory MDVSA-2015:073
http://www.mandriva.com/en/
______________________________
Package : openldap
Date : March 27, 2015
Affected: Business Server 2.0
______________________________
Problem Description:
Multiple vulnerabilities has been discovered and corrected in openldap:
The deref_parseCtrl function in servers/slapd/overlays/deref.c in
OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a
denial of service (NULL pointer dereference and crash) via an empty
attribute list in a deref control in a search request (CVE-2015-1545).
Double free vulnerability in the get_vrFilter function in
servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to
cause a denial of service (crash) via a crafted search query with a
matched values control (CVE-2015-1546).
The updated packages provides a solution for these security issues.
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
______________________________
Updated Packages:
Mandriva Business Server 2/X86_64:
8cf3267fdb2dd7fe3e3d45560bdb21
865d9a982ce84212ac326c3c1e765b
5257553f4101f109f611fb4a1169e0
559e20b8fb73db0a2596ae53debb11
d768c2cfd50d48df2c6d50cba2804f
ca1be9bfd5f8494412dacd1704446a
10616f8ee850c96f6f31a56c04b2f5
abe8987076d7c071cf0556717824f9
167cde52384ff479dbf66c9c3b9c18
7bb0cde0c37e82616d7e1c2f51339e
fa9deaf6135eb3443dfa4ea2d5906d
712530d38d7091f1feab1b0f214d84
e2a1576a5731e854ac0395c65014b8
38e739f91027490ef87474d6053b66
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą