First published: Fri Feb 01 2008(Updated: )
It was discovered that modify operation with NOOP control on an entry stored in BDB backed can cause OpenLDAP's slapd daemon to crash. Further details and patch can be found in upstream bug / CVS: <a href="http://www.openldap.org/its/index.cgi/Software%20Bugs?id=4925">http://www.openldap.org/its/index.cgi/Software%20Bugs?id=4925</a> <a href="http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modify.c.diff?r1=1.124.2.16&r2=1.124.2.17&f=h">http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modify.c.diff?r1=1.124.2.16&r2=1.124.2.17&f=h</a> NOOP control was introduced in OpenLDAP 2.1 branch as documented on roadmap page: <a href="http://www.openldap.org/software/roadmap.html">http://www.openldap.org/software/roadmap.html</a> This issue was fixed upstream in version 2.3.36: <a href="http://www.openldap.org/devel/cvsweb.cgi/~checkout~/Attic/CHANGES?rev=1.5.8.414">http://www.openldap.org/devel/cvsweb.cgi/~checkout~/Attic/CHANGES?rev=1.5.8.414</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openldap Openldap | <=2.3.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.