U radu programskog paketa OpenLDAP, za operacijski sustav Fedora 14, uočena su tri sigurnosna propusta. Udaljenom napadaču omogućuju izvođenje napada uskraćivanja usluge i obilaženje određenih sigurnosnih ograničenja.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-3627
2011-03-19 09:56:57
--------------------------------------------------------------------------------
Name : openldap
Product : Fedora 14
Version : 2.4.23
Release : 10.fc14
URL : http://www.openldap.org/
Summary : LDAP support libraries
Description :
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools. LDAP is a set of
protocols for accessing directory services (usually phone book style
information, but other information is possible) over the Internet,
similar to the way DNS (Domain Name System) information is propagated
over the Internet. The openldap package contains configuration files,
libraries, and documentation for OpenLDAP.
--------------------------------------------------------------------------------
Update Information:
Changes not covered by bugs:
- removed slurpd options from sysconfig/ldap
- fix: possible null pointer dereference in NSS implementation
--------------------------------------------------------------------------------
ChangeLog:
* Sat Mar 19 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-10
- fix update: openldap can't use TLS after a fork() (#636956)
- fix: possible null pointer dereference in NSS implementation
- fix: openldap-servers upgrade hangs or do not upgrade the database (#664433)
* Tue Mar 1 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-9
- fix: CVE-2011-1024 ppolicy forwarded bind failure messages cause success
(#680466)
- fix: CVE-2011-1025 rootpw is not verified for ndb backend (#680472)
- fix: security - DoS when submitting special MODRDN request (#680975)
* Wed Feb 2 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-8
- fix update: openldap can't use TLS after a fork() (#636956)
* Tue Jan 25 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-7
- fix: openldap can't use TLS after a fork() (#636956)
- fix: openldap-server upgrade gets stuck when the database is damaged
(#664433)
* Thu Jan 20 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-6
- fix: some server certificates refused with inadequate type error (#668899)
- fix: default encryption strength dropped in switch to using NSS (#669446)
* Thu Jan 6 2011 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-5
- initscript: slaptest with '-u' to skip database opening (#667768)
- removed slurpd options from sysconfig/ldap
- fix: verification of self issued certificates (#657984)
* Mon Nov 22 2010 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-4
- Mozilla NSS - implement full non-blocking semantics
ldapsearch -Z hangs server if starttls fails (#652822)
- updated list of all overlays in slapd.conf (#655899)
- fix database upgrade process (#656257)
* Thu Nov 18 2010 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-3
- add support for multiple prefixed Mozilla NSS database files in
TLS_CACERTDIR
- reject non-file keyfiles in TLS_CACERTDIR (#652315)
- TLS_CACERTDIR precedence over TLS_CACERT (#652304)
- accept only files in hash.0 format in TLS_CACERTDIR (#650288)
- improve SSL/TLS trace messages (#652818)
* Mon Nov 1 2010 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-2
- fix possible infinite loop when checking permissions of TLS files (#641946)
- removed outdated autofs.schema (#643045)
- removed outdated README.upgrade
- removed relics of migrationtools
* Fri Aug 27 2010 Jan Vcelak <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.4.23-1
- rebase to 2.4.23
- embeded db4 library removed
- removed bogus links in "SEE ALSO" in several man-pages (#624616)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #680466 - CVE-2011-1024 openldap: forwarded bind failure messages
cause success
https://bugzilla.redhat.com/show_bug.cgi?id=680466
[ 2 ] Bug #680472 - CVE-2011-1025 openldap: rootpw not verified via
slapd.conf when using the NDB backend
https://bugzilla.redhat.com/show_bug.cgi?id=680472
[ 3 ] Bug #680975 - CVE-2011-1081 openldap: DoS when submitting special
MODRDN request
https://bugzilla.redhat.com/show_bug.cgi?id=680975
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update openldap' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke