USN-2622-1
Dashboard / Vulnerabilities / USN-2622-1
USN-2622-1
Summary: openldap vulnerabilities
Details: It was discovered that OpenLDAP incorrectly handled certain search queries that returned empty attributes. A remote attacker could use this issue to cause OpenLDAP to assert, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS. (CVE-2012-1164) Michael Vishchers discovered that OpenLDAP improperly counted references when the rwm overlay was used. A remote attacker could use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449) It was discovered that OpenLDAP incorrectly handled certain empty attribute lists in search requests. A remote attacker could use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2015-1545)
References: https://ubuntu.com/security/notices/USN-2622-1, https://ubuntu.com/security/CVE-2012-1164, https://ubuntu.com/security/CVE-2013-4449, https://ubuntu.com/security/CVE-2015-1545
Affected packages
Package
Name: openldap
Purl: pkg:deb/ubuntu/[email protected]+nmu2ubuntu8.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
