MGASA-2014-0062
Dashboard / Vulnerabilities / MGASA-2014-0062
Summary: Updated openldap packages fix security vulnerability
Details: A denial of service flaw was found in the way the OpenLDAP server daemon (slapd) performed reference counting when using the rwm (rewrite/remap) overlay. A remote attacker able to query the OpenLDAP server could use this flaw to crash the server by immediately unbinding from the server after sending a search request (CVE-2013-4449).
References: https://advisories.mageia.org/MGASA-2014-0062.html, http://www.openldap.org/its/index.cgi/Incoming?id=7723, https://rhn.redhat.com/errata/RHSA-2014-0126.html, https://bugs.mageia.org/show_bug.cgi?id=12586
Affected packages
Package
Name: openldap
Purl: pkg:rpm/mageia/openldap?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
