OESA-2021-1119
Dashboard / Vulnerabilities / OESA-2021-1119
Summary: openldap security update
Details: OpenLDAP is an open source suite of LDAP (Lightweight Directory Access Protocol) applications and development tools. LDAP is a set of protocols for accessing directory services (usually phone book style information, but other information is possible) over the Internet, similar to the way DNS (Domain Name System) information is propagated over the Internet. The openldap package contains configuration files, libraries, and documentation for OpenLDAP. Security Fix(es): In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.(CVE-2021-27212)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1119, https://nvd.nist.gov/vuln/detail/CVE-2021-27212
Affected packages
Package
Name: openldap
Purl: pkg:rpm/openEuler/openldap&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
