漏洞信息详情
OpenLDAP slapd/back-bdb/modrdn.c 拒绝服务漏洞
漏洞简介
OpenLDAP的BDB slapd backend中的slapd/back-bdb/modrdn.c存在拒绝服务漏洞。远程认证用户可以借助一个带有NOOP(LDAP_X_NO_OPERATION) control的modrdn操作引起拒绝服务攻击(后台程序崩溃)。该漏洞与CVE-2007-6698有关。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
OpenLDAP OpenLDAP 2.3.39
OpenLDAP modrdn.c version 1.198 patch
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&hideattic=1&sortbydate=0
参考网址
来源: VUPEN
名称: ADV-2009-3184
链接:http://www.vupen.com/english/advisories/2009/3184
来源: SECTRACK
名称: 1019481
链接:http://www.securitytracker.com/id?1019481
来源: BID
名称: 27778
链接:http://www.securityfocus.com/bid/27778
来源: BUGTRAQ
名称: 20080212 rPSA-2008-0059-1 openldap openldap-clients openldap-servers
链接:http://www.securityfocus.com/archive/1/archive/1/488242/100/200/threaded
来源: REDHAT
名称: RHSA-2008:0110
链接:http://www.redhat.com/support/errata/RHSA-2008-0110.html
来源: www.openldap.org
链接:http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358
来源: www.openldap.org
链接:http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&f=h
来源: VUPEN
名称: ADV-2008-0536
链接:http://www.frsirt.com/english/advisories/2008/0536/references
来源: wiki.rpath.com
链接:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0059
来源: wiki.rpath.com
链接:http://wiki.rpath.com/Advisories:rPSA-2008-0059
来源: support.apple.com
链接:http://support.apple.com/kb/HT3937
来源: SECUNIA
名称: 29068
链接:http://secunia.com/advisories/29068
来源: SECUNIA
名称: 28953
链接:http://secunia.com/advisories/28953
来源: SECUNIA
名称: 28926
链接:http://secunia.com/advisories/28926
来源: SECUNIA
名称: 28914
链接:http://secunia.com/advisories/28914
来源: APPLE
名称: APPLE-SA-2009-11-09-1
链接:http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
来源: XF
名称: openldap-modrdn-dos(40479)
链接:http://xforce.iss.net/xforce/xfdb/40479
来源: UBUNTU
名称: USN-584-1
链接:http://www.ubuntu.com/usn/usn-584-1
来源: MANDRIVA
名称: MDVSA-2008:058
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:058
来源: DEBIAN
名称: DSA-1541
链接:http://www.debian.org/security/2008/dsa-1541
来源: GENTOO
名称: GLSA-200803-28
链接:http://security.gentoo.org/glsa/glsa-200803-28.xml
来源: SECUNIA
名称: 29957
链接:http://secunia.com/advisories/29957
来源: SECUNIA
名称: 29682
链接:http://secunia.com/advisories/29682
来源: SECUNIA
名称: 29461
链接:http://secunia.com/advisories/29461
来源: SECUNIA
名称: 29256
链接:http://secunia.com/advisories/29256
来源: SECUNIA
名称: 29225
链接:http://secunia.com/advisories/29225
来源: SUSE
名称: SUSE-SR:2008:010
链接:http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html
受影响实体
- Openldap Openldap:2.3.39<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...