Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2019.0280
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2019-0280)
Summary:The remote host is missing an update for the 'openldap' package(s) announced via the MGASA-2019-0280 advisory.
Description:Summary:
The remote host is missing an update for the 'openldap' package(s) announced via the MGASA-2019-0280 advisory.

Vulnerability Insight:
Updated openldap packages fix security vulnerabilities:
It was discovered that OpenLDAP incorrectly handled rootDN delegation.
A database administrator could use this issue to request authorization
as an identity from another database, contrary to expectations
(CVE-2019-13057).

It was discovered that OpenLDAP incorrectly handled SASL authentication
and session encryption. After a first SASL bind was completed, it was
possible to obtain access by performing simple binds, contrary to
expectations (CVE-2019-13565).

Affected Software/OS:
'openldap' package(s) on Mageia 6, Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-13057
Bugtraq: 20191211 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra (Google Search)
https://seclists.org/bugtraq/2019/Dec/23
https://kc.mcafee.com/corporate/index?page=content&id=SB10365
https://security.netapp.com/advisory/ntap-20190822-0004/
https://support.apple.com/kb/HT210788
https://www.openldap.org/lists/openldap-announce/201907/msg00001.html
http://seclists.org/fulldisclosure/2019/Dec/26
https://www.openldap.org/its/?findid=9038
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html
SuSE Security Announcement: openSUSE-SU-2019:2157 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html
SuSE Security Announcement: openSUSE-SU-2019:2176 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html
https://usn.ubuntu.com/4078-1/
https://usn.ubuntu.com/4078-2/
Common Vulnerability Exposure (CVE) ID: CVE-2019-13565
https://support.f5.com/csp/article/K98008862?utm_source=f5support&utm_medium=RSS
https://www.openldap.org/its/index.cgi/?findid=9052
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.