SUSE-SU-2015:1077-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1077-1
SUSE-SU-2015:1077-1
Summary: Security update for openldap2
Details: openldap2 was updated to fix two security issues and one non-security bug. The following vulnerabilities were fixed: * A remote attacker could cause a denial of service through a NULL pointer dereference and crash via an empty attribute list in a deref control in a search request. (bnc#916897 CVE-2015-1545) * A remote attacker could cause a denial of service (crash) via a crafted search query with a matched values control. (bnc#916914 CVE-2015-1546) The following non-security issue was fixed: * Prevent connection-0 (internal connection) from showing up in the monitor backend (bnc#905959)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151077-1/, https://bugzilla.suse.com/905959, https://bugzilla.suse.com/916897, https://bugzilla.suse.com/916914, https://www.suse.com/security/cve/CVE-2015-1545, https://www.suse.com/security/cve/CVE-2015-1546
Affected packages
Package
Name: openldap2-client
Purl: pkg:rpm/suse/openldap2-client&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
