Saturday, July 24, 2010

Red Hat Enterprise Linux

Amplify’d from www.criticalwatch.com
RHSA-2010:0542-01: RHSA-2010:0542-01 Moderate: openldap security update
Red Hat Enterprise Linux
Description:



OpenLDAP is an open source suite of LDAP (Lightweight Directory Access

Protocol) applications and development tools.



Multiple flaws were discovered in the way the slapd daemon handled modify

relative distinguished name (modrdn) requests. An authenticated user with

privileges to perform modrdn operations could use these flaws to crash the

slapd daemon via specially-crafted modrdn requests. (CVE-2010-0211,

CVE-2010-0212)



Red Hat would like to thank CERT-FI for responsibly reporting these flaws,

who credit Ilkka Mattila and Tuomas Salomki for the discovery of the

issues.



Users of OpenLDAP should upgrade to these updated packages, which contain

a backported patch to correct these issues. After installing this update,

the OpenLDAP daemons will be restarted automatically.Read more at www.criticalwatch.com
 

No comments:

Post a Comment