Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.122377
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2010-0198)
Summary:The remote host is missing an update for the 'openldap' package(s) announced via the ELSA-2010-0198 advisory.
Description:Summary:
The remote host is missing an update for the 'openldap' package(s) announced via the ELSA-2010-0198 advisory.

Vulnerability Insight:
[2.3.43-12]
- updated spec file, so the compat-libs linking patch applies
correctly

[2.3.43-11]
- backported patch to handle null character in TLS
certificates (#560912)

[2.3.43-10]
- updated chase-referral patch to compile cleanly
- updated init script (#562714)

[2.3.43-9]
- updated ldap.sysconf to include SLAPD_LDAP, SLAPD_LDAPS and
SLAPD_LDAPI options (#559520)

[2.3.43-8]
- fixed connection freeze when TLSVerifyClient = allow (#509230)

[2.3.43-7]
- fixed chasing referrals in libldap (#510522)

[2.3.43-6]
- fixed possible double free() in rwm overlay (#495628)
- updated slapd man page and slapcat usage string (#468206)
- updated default config for slapd - deleted syncprov module (#466937)
- fixed migration tools autofs generated format (#460331)
- fixed migration tools numbers detection in /etc/shadow (#113857)
- fixed migration tools base ldif (#104585)

[2.3.43-5]
- implementation of limit adjustment before starting slapd (#527313)
- init script no longer executes script in /tmp (#483356)
- slapd not starting with ldap:/// every time (#481003)
- delay between TERM and KILL when shutting down slapd (#452064)

[2.3.43-4]
- fixed compat libs linking (#503734)
- activated lightweight dispatcher feature (#507276)
- detection of timeout after failed result (#495701

Affected Software/OS:
'openldap' package(s) on Oracle Linux 5.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3767
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html
http://security.gentoo.org/glsa/glsa-201406-36.xml
http://marc.info/?l=oss-security&m=125198917018936&w=2
http://marc.info/?l=oss-security&m=125369675820512&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274
http://www.redhat.com/support/errata/RHSA-2010-0543.html
http://www.redhat.com/support/errata/RHSA-2011-0896.html
http://secunia.com/advisories/38769
http://secunia.com/advisories/40677
SuSE Security Announcement: SUSE-SR:2009:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
http://www.vupen.com/english/advisories/2009/3056
http://www.vupen.com/english/advisories/2010/1858
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.