GLSA: openldap

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 12/28/02

  • Next message: Daniel Ahlberg: "GLSA: cups"
    From: Daniel Ahlberg <aliz@gentoo.org>
    Date: Sat, 28 Dec 2002 01:10:13 +0100
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200212-12
    - - --------------------------------------------------------------------

    PACKAGE : openldap
    SUMMARY : remote command execution
    DATE    : 2002-12-28 00:12 UTC
    EXPLOIT : remote

    - - --------------------------------------------------------------------

    - From SuSE Security Advisory SuSE-SA:2002:047:

    "The SuSE Security Team reviewed critical parts of that package and
    found several buffer overflows and other bugs remote attackers could
    exploit to gain access on systems running vulnerable LDAP servers.
    In addition to these bugs, various local exploitable bugs within the
    OpenLDAP2 libraries (openldap2-devel package) have been fixed."

    Read the full advisory at
    http://www.suse.de/de/security/2002_047_openldap2.html

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-nds/openldap-2.0.25-r2 update their systems as follows:

    emerge rsync
    emerge openldap
    emerge clean

    - - --------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    raker@gentoo.org
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+DOvXfT7nyhUpoZMRAosUAJwLfUla5RD/VxF7WHAm8ZAbbFYgmACgugyg
    WemCvhFKS9lr6lCJpOS3Nyo=
    =Oga0
    -----END PGP SIGNATURE-----



    Relevant Pages

    • [Full-Disclosure] GLSA: openldap
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200212-12 ... PACKAGE: openldap ... SUMMARY: remote command execution ...
      (Full-Disclosure)
    • SuSE Security Announcement: openssh (second release) (SuSE-SA:2003:039)
      ... packages preserving the package version to avoid the risk of incompatible ... If exploited by a (remote) attacker, ... the ssh daemon with this update. ... will release them with a SuSE Security Announcement as soon as possible. ...
      (Bugtraq)
    • RE: Unknown App
      ... package refers to "cmd.exe", ... In case of remote test the most simple solution would be nmap's -A switch or ... > Bureau of Diplomatic Security ... > Subject: Unknown App ...
      (Pen-Test)
    • [Full-Disclosure] SuSE Security Announcement: openssh (second release) (SuSE-SA:2003:039)
      ... packages preserving the package version to avoid the risk of incompatible ... If exploited by a (remote) attacker, ... the ssh daemon with this update. ... will release them with a SuSE Security Announcement as soon as possible. ...
      (Full-Disclosure)
    • GLSA: MailTools
      ... SUMMARY: remote command execution ... The SuSE Security Team reviewed critical Perl modules, ... Mail::Mailer package. ... This is due to the usage of mailx as default mailer which allows commands ...
      (Bugtraq)