First published: Thu Sep 07 2006(Updated: )
slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenLDAP Servers | =2.0.20 | |
Red Hat OpenLDAP Servers | =2.0.21 | |
Red Hat OpenLDAP Servers | =2.0.22 | |
Red Hat OpenLDAP Servers | =2.0.23 | |
Red Hat OpenLDAP Servers | =2.0.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4600 is considered a medium severity vulnerability due to the potential for arbitrary modifications by authenticated users.
To mitigate CVE-2006-4600, upgrade OpenLDAP to version 2.3.25 or later.
CVE-2006-4600 affects OpenLDAP versions 2.0.20 to 2.0.24.
CVE-2006-4600 can be exploited by authenticated users who have selfwrite ACL privileges to modify Distinguished Names.
Exploitation of CVE-2006-4600 could lead to unauthorized modifications of directory entries, potentially compromising data integrity.