Bug 431203 (CVE-2007-6698)
Summary: | CVE-2007-6698 openldap: slapd crash on NOOP control operation on entry in bdb storage | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | unspecified | CC: | jplans, jsafrane, kreilly, psklenar | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2008-02-22 08:45:03 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 431405, 431406, 431407, 431408, 431409 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Tomas Hoger
2008-02-01 14:57:49 UTC
This issue does not affect OpenLDAP packages as shipped in Red Hat Enterprise Linux 2.1 and 3. OpenLDAP packages in Red Hat Enterprise Linux 4 and 5 are affected and issue will be addressed in the security advisory. Note: On Red Hat Enterprise Linux 5, database recovery performed during slapd daemon startup may not properly clean up after the crash caused by such request with NOOP control. Affected DN may remain locked / unaccessible via LDAP requests. If this occurs, you need to run database recovery manually using following command: slapd_db_recover -v -h /var/lib/ldap while slapd daemon is stopped. openldap-2.3.34-6.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report. This issue was addressed in: Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2008-0110.html Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-1307 |