A flaw was found in the way the OpenLDAP server daemon (slapd) parsed certain BER data. A remote attacker could use this flaw to crash slapd via a specially crafted packet. Upstream advisory (including a reproducer): http://www.openldap.org/its/index.cgi/Software%20Bugs?id=8240 Upstream patch: http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=6fe51a9ab04fd28bbc171da3cf12f1c1040d6629 CVE assignment request: http://seclists.org/oss-sec/2015/q3/535
Created openldap tracking bugs for this issue: Affects: fedora-all [bug 1262396]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2015:1840 https://rhn.redhat.com/errata/RHSA-2015-1840.html