Updated openldap packages available
| Advisory: | RHSA-2003:040-07 |
|---|---|
| Type: | Security Advisory |
| Severity: | N/A |
| Issued on: | 2003-02-06 |
| Last updated on: | 2003-02-05 |
| Affected Products: | Red Hat Linux 6.2 Red Hat Linux 7.0 Red Hat Linux 7.1 Red Hat Linux 7.2 Red Hat Linux 7.3 Red Hat Linux 8.0 |
| CVEs (cve.mitre.org): |
CVE-2002-1378 CVE-2002-1379 CVE-2002-1508 |
Details
Updated openldap packages are available which fix a number of local and
remote buffer overflows in libldap and the slapd and slurpd servers, and
potential issues stemming from using user-specified LDAP configuration files.
OpenLDAP is a suite of LDAP (Lightweight Directory Access Protocol)
applications and development tools. LDAP is a set of protocols for
accessing directory services. In an audit of OpenLDAP by SuSE, a number of
potential security issues were found:
When reading configuration files, libldap would read the current user's
.ldaprc file even in applications being run with elevated privileges.
Slurpd would overflow an internal buffer if the command-line argument used
with the -t or -r flags was too long, or if the name of a file for which it
attempted to create an advisory lock was too long.
When parsing filters, the getfilter family of functions from libldap could
be made to overflow an internal buffer by supplying a carefully crafted
ldapfilter.conf file.
When processing LDAP entry display templates, libldap could be made to
overflow an internal buffer by supplying a properly crafted
ldaptemplates.conf file.
When parsing an access control list, slapd could be made to overflow an
internal buffer.
When constructing the name of the file used for logging rejected
replication requests, slapd would overflow an internal buffer if the size
of the generated name was too large, and could be tricked into destroying
the contents of any file owned by the ldap user due to a race condition in
the subsequent creation of the log file.
Red Hat Linux users who use LDAP are advised to install the updated
openldap packages which are not vulnerable to these issues.
Solution
relevant to your system have been applied.
To update all RPMs for your particular architecture, run:
rpm -Fvh [filenames]
where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.
Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Updated packages
| Red Hat Linux 6.2 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/1.2.13-2/SRPMS/openldap-1.2.13-2.src.rpm Missing file |
MD5: 6abc37d341ed1998e0e37a5c8ae2b292 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/1.2.13-2/i386/openldap-1.2.13-2.i386.rpm Missing file |
MD5: 2d6741aa454a4bf6ad39447e30136b05 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/1.2.13-2/i386/openldap-clients-1.2.13-2.i386.rpm Missing file |
MD5: c5d39f85114ba91e94fe270c2b04a12e |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/1.2.13-2/i386/openldap-devel-1.2.13-2.i386.rpm Missing file |
MD5: 1ae2c495fb0dd934ac51365c0b6cb098 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/1.2.13-2/i386/openldap-servers-1.2.13-2.i386.rpm Missing file |
MD5: e3c1cffb180a025811cf6a97d95c7e33 |
| Red Hat Linux 7.0 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.1/SRPMS/openldap-2.0.27-2.7.1.src.rpm Missing file |
MD5: edde5757c10e2f51a371f457cb3d4bee |
| ftp://updates.redhat.com/rhn/public/2703533/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.1/i386/openldap-2.0.27-2.7.1.i386.rpm Missing file |
MD5: a44a25cea2e81cb296d2aad1351a750d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.7.1/i386/openldap-clients-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 48b8097de61282171ecb2740116ea63f |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.7.1/i386/openldap-devel-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 23f437d646397bebed28fad5b733ee8f |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.7.1/i386/openldap-servers-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 94e6f4fc6851055fa3a224ea30b693a5 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/i386/openldap12-1.2.13-8.i386.rpm Missing file |
MD5: 0a692fe198ed8743ede8e6dbf999e486 |
| Red Hat Linux 7.1 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.1/SRPMS/openldap-2.0.27-2.7.1.src.rpm Missing file |
MD5: edde5757c10e2f51a371f457cb3d4bee |
| ftp://updates.redhat.com/rhn/public/2703533/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.1/i386/openldap-2.0.27-2.7.1.i386.rpm Missing file |
MD5: a44a25cea2e81cb296d2aad1351a750d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.7.1/i386/openldap-clients-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 48b8097de61282171ecb2740116ea63f |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.7.1/i386/openldap-devel-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 23f437d646397bebed28fad5b733ee8f |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.7.1/i386/openldap-servers-2.0.27-2.7.1.i386.rpm Missing file |
MD5: 94e6f4fc6851055fa3a224ea30b693a5 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/i386/openldap12-1.2.13-8.i386.rpm Missing file |
MD5: 0a692fe198ed8743ede8e6dbf999e486 |
| Red Hat Linux 7.2 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/public/2703533/openldap/2.0.27-2.7.3/SRPMS/openldap-2.0.27-2.7.3.src.rpm Missing file |
MD5: 148ac6c282678e649d9bc82ef68472ec |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.3/SRPMS/openldap-2.0.27-2.7.3.src.rpm Missing file |
MD5: 148ac6c282678e649d9bc82ef68472ec |
| ftp://updates.redhat.com/rhn/public/2703533/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.3/i386/openldap-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 878a1302654284097cd6b1ff37dcb990 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.7.3/i386/openldap-clients-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 42bdf5437712c8b7240cdb6dee4ec8c1 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.7.3/i386/openldap-devel-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 4fedaaa2c3bae85580d80b981af12194 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.7.3/i386/openldap-servers-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 9341c678193d6f6dda7c9718df75d614 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/i386/openldap12-1.2.13-8.i386.rpm Missing file |
MD5: 0a692fe198ed8743ede8e6dbf999e486 |
| IA-64: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.3/ia64/openldap-2.0.27-2.7.3.ia64.rpm Missing file |
MD5: 518f368e458a617daa37baefb331fa09 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.7.3/ia64/openldap-clients-2.0.27-2.7.3.ia64.rpm Missing file |
MD5: c5b77b9c6a01f72f13438d058ec05cb9 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.7.3/ia64/openldap-devel-2.0.27-2.7.3.ia64.rpm Missing file |
MD5: 55e81b9cb1e2ae1a44ceb833470087ee |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.7.3/ia64/openldap-servers-2.0.27-2.7.3.ia64.rpm Missing file |
MD5: 5c6dd70a327ced63f143eee0587e9439 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/ia64/openldap12-1.2.13-8.ia64.rpm Missing file |
MD5: fccda5abf8c02f80a5713438854ccb39 |
| Red Hat Linux 7.3 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/public/2703533/openldap/2.0.27-2.7.3/SRPMS/openldap-2.0.27-2.7.3.src.rpm Missing file |
MD5: 148ac6c282678e649d9bc82ef68472ec |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.3/SRPMS/openldap-2.0.27-2.7.3.src.rpm Missing file |
MD5: 148ac6c282678e649d9bc82ef68472ec |
| ftp://updates.redhat.com/rhn/public/2703533/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/SRPMS/openldap12-1.2.13-8.src.rpm Missing file |
MD5: 92d8d3db8064d35faab46b59c077251d |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.7.3/i386/openldap-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 878a1302654284097cd6b1ff37dcb990 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.7.3/i386/openldap-clients-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 42bdf5437712c8b7240cdb6dee4ec8c1 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.7.3/i386/openldap-devel-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 4fedaaa2c3bae85580d80b981af12194 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.7.3/i386/openldap-servers-2.0.27-2.7.3.i386.rpm Missing file |
MD5: 9341c678193d6f6dda7c9718df75d614 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-8/i386/openldap12-1.2.13-8.i386.rpm Missing file |
MD5: 0a692fe198ed8743ede8e6dbf999e486 |
| Red Hat Linux 8.0 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.8.0/SRPMS/openldap-2.0.27-2.8.0.src.rpm Missing file |
MD5: cb6f6d639ff823cc016725dab752aacd |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-9/SRPMS/openldap12-1.2.13-9.src.rpm Missing file |
MD5: 2ba981c5834886ca93ce492ea8c87848 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap/2.0.27-2.8.0/i386/openldap-2.0.27-2.8.0.i386.rpm Missing file |
MD5: f6ffab19ae521c65396cc76d0a64c2c9 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-clients/2.0.27-2.8.0/i386/openldap-clients-2.0.27-2.8.0.i386.rpm Missing file |
MD5: 3e12f7f0aacca920d60fc39766b7d3e5 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-devel/2.0.27-2.8.0/i386/openldap-devel-2.0.27-2.8.0.i386.rpm Missing file |
MD5: 351bd4cea012a1517ded0c03a4512c48 |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap-servers/2.0.27-2.8.0/i386/openldap-servers-2.0.27-2.8.0.i386.rpm Missing file |
MD5: a5b8e07d9f13a98aaf1bf999d6672efc |
| ftp://updates.redhat.com/rhn/repository/NULL/openldap12/1.2.13-9/i386/openldap12-1.2.13-9.i386.rpm Missing file |
MD5: 0e5cbc3c9eb9136169caefed4dadd7c6 |
References
https://www.redhat.com/security/data/cve/CVE-2002-1379.html
https://www.redhat.com/security/data/cve/CVE-2002-1508.html
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/