This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 432008 - (CVE-2008-0658) CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage
CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on ...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
source=vendorsec,reported=20080207,pu...
: Security
Depends On: 431405 431406 431407 431408 432012 432013 432014
Blocks:
  Show dependency treegraph
 
Reported: 2008-02-08 07:47 EST by Tomas Hoger
Modified: 2008-02-22 03:45 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-02-22 03:45:14 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Tomas Hoger 2008-02-08 07:47:13 EST
While preparing the patch for CVE-2007-6698 (issue allowing slapd daemon crash
using modify requests with NOOP control, tracked via bug bug #431203), it was
discovered, that similar crash can be achieved using modrdn operation with NOOP
control.

Upstream bug report:
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358

Patch applied in upstream CVS:
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-bdb/modrdn.c.diff?r1=1.197&r2=1.198&f=h
Comment 3 Tomas Hoger 2008-02-08 08:39:02 EST
Similar to CVE-2007-6698, this issue does not affect OpenLDAP packages as
shipped in Red Hat Enterprise Linux 2.1 and 3, as they do not support NOOP
controls.  Packages shipped in Red Hat Enterprise Linux 4 and 5 are affected.
Comment 4 Fedora Update System 2008-02-11 02:38:03 EST
openldap-2.3.39-3.fc8 has been submitted as an update for Fedora 8
Comment 5 Fedora Update System 2008-02-11 02:39:01 EST
openldap-2.3.34-7.fc7 has been submitted as an update for Fedora 7
Comment 6 Fedora Update System 2008-02-13 00:10:59 EST
openldap-2.3.39-3.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2008-02-13 00:15:41 EST
openldap-2.3.34-7.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.