Updated OpenLDAP packages are now available for Red Hat Linux 7, 7.1, and
7.2. These updates resolve a vulnerability which would allow users to
remove non-mandatory attributes from any object in a directory.
Versions of OpenLDAP from 2.0.0 through 2.0.19 do not check permissions
using access control lists when a user attempts to remove an attribute from
an object in the directory by replacing its values with an empty list.
Because schema checking is still enforced, a user can only remove
attributes which the schema does not require the object to possess.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2002-0045 to this issue.
These packages update OpenLDAP to version 2.0.21 which is not vulnerable to
this problem.
| Red Hat Linux 7.0 |
|
| SRPMS: |
openldap-2.0.21-0.7.1.src.rpm
File outdated by: RHSA-2003:040 |
621a273d4fd00814d9f5be4952e1da24 |
| |
| Alpha: |
ftp://updates.redhat.com/7.0/en/os/alpha/openldap-2.0.21-0.7.1.alpha.rpm
Missing file |
adb5c0f9f48c628e838e10d9209ca33e |
ftp://updates.redhat.com/7.0/en/os/alpha/openldap-clients-2.0.21-0.7.1.alpha.rpm
Missing file |
2fff8e15781a76117ffc849bf8c196e0 |
ftp://updates.redhat.com/7.0/en/os/alpha/openldap-devel-2.0.21-0.7.1.alpha.rpm
Missing file |
0afbfe730aafb65faf84302ec3f1fb89 |
ftp://updates.redhat.com/7.0/en/os/alpha/openldap-servers-2.0.21-0.7.1.alpha.rpm
Missing file |
ec6df8d880e76595ae1d7772a09a8ded |
| |
| IA-32: |
openldap-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
4c9884f16c8c6faae1311b5f7f53e7a9 |
openldap-clients-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
1381cc0aee8127b57bc621ff8df6b52f |
openldap-devel-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
739ceb89c3c88198e2145b3a661a1fb4 |
openldap-servers-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
970ebb03d448f637c07b6cf7b419cd8b |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
openldap-2.0.21-0.7.1.src.rpm
File outdated by: RHSA-2003:040 |
621a273d4fd00814d9f5be4952e1da24 |
| |
| Alpha: |
ftp://updates.redhat.com/7.1/en/os/alpha/openldap-2.0.21-0.7.1.alpha.rpm
Missing file |
adb5c0f9f48c628e838e10d9209ca33e |
ftp://updates.redhat.com/7.1/en/os/alpha/openldap-clients-2.0.21-0.7.1.alpha.rpm
Missing file |
2fff8e15781a76117ffc849bf8c196e0 |
ftp://updates.redhat.com/7.1/en/os/alpha/openldap-devel-2.0.21-0.7.1.alpha.rpm
Missing file |
0afbfe730aafb65faf84302ec3f1fb89 |
ftp://updates.redhat.com/7.1/en/os/alpha/openldap-servers-2.0.21-0.7.1.alpha.rpm
Missing file |
ec6df8d880e76595ae1d7772a09a8ded |
| |
| IA-32: |
openldap-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
4c9884f16c8c6faae1311b5f7f53e7a9 |
openldap-clients-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
1381cc0aee8127b57bc621ff8df6b52f |
openldap-devel-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
739ceb89c3c88198e2145b3a661a1fb4 |
openldap-servers-2.0.21-0.7.1.i386.rpm
File outdated by: RHSA-2003:040 |
970ebb03d448f637c07b6cf7b419cd8b |
| |
| IA-64: |
ftp://updates.redhat.com/7.1/en/os/ia64/openldap-2.0.21-0.7.1.ia64.rpm
Missing file |
14bd6db0758dc071f8e23339d15b2220 |
ftp://updates.redhat.com/7.1/en/os/ia64/openldap-clients-2.0.21-0.7.1.ia64.rpm
Missing file |
f88040707cc20e71f4b94da154b8ef43 |
ftp://updates.redhat.com/7.1/en/os/ia64/openldap-devel-2.0.21-0.7.1.ia64.rpm
Missing file |
3cb633c9f7ed221c45f2701da7c8dd7e |
ftp://updates.redhat.com/7.1/en/os/ia64/openldap-servers-2.0.21-0.7.1.ia64.rpm
Missing file |
c01d0d619c62fced192418cdeddcae76 |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
openldap-2.0.21-1.src.rpm
File outdated by: RHSA-2003:040 |
baad341d94bae309895765c10fd397cd |
| |
| IA-32: |
openldap-2.0.21-1.i386.rpm
File outdated by: RHSA-2003:040 |
d6b0b4383d02c0c26b3b146384b238fb |
openldap-clients-2.0.21-1.i386.rpm
File outdated by: RHSA-2003:040 |
8bec3cac0671d97b8f68895c2a3a0a27 |
openldap-devel-2.0.21-1.i386.rpm
File outdated by: RHSA-2003:040 |
38165c13288cee96680fb35368ca1c7b |
openldap-servers-2.0.21-1.i386.rpm
File outdated by: RHSA-2003:040 |
0f74a1e19ac767ce3e1a2b0b4a9a99ef |
| |
| IA-64: |
openldap-2.0.21-1.ia64.rpm
File outdated by: RHSA-2003:040 |
4685917c60c02f0c1ce0eaac2ed53136 |
openldap-clients-2.0.21-1.ia64.rpm
File outdated by: RHSA-2003:040 |
397407675083f4d44692313f077a5dc0 |
openldap-devel-2.0.21-1.ia64.rpm
File outdated by: RHSA-2003:040 |
5643cbabd72ac60145212f915fc5fa21 |
openldap-servers-2.0.21-1.ia64.rpm
File outdated by: RHSA-2003:040 |
5d62ffeedcdd02b9f41f77ea0fd65ecf |
| |
| s390: |
ftp://updates.redhat.com/7.2/en/os/s390/openldap-2.0.21-1.s390.rpm
Missing file |
033b5f6901e5d15695051b4a6cb9bba8 |
ftp://updates.redhat.com/7.2/en/os/s390/openldap-clients-2.0.21-1.s390.rpm
Missing file |
e8775603d6ee98b6d29b2c2313ace0ec |
ftp://updates.redhat.com/7.2/en/os/s390/openldap-devel-2.0.21-1.s390.rpm
Missing file |
50bde8967df17303b5f3dae2f5fafb1d |
ftp://updates.redhat.com/7.2/en/os/s390/openldap-servers-2.0.21-1.s390.rpm
Missing file |
27e25165a51c93508f73633ebe680e09 |
| |