Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123891
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2012-0899)
Summary:The remote host is missing an update for the 'openldap' package(s) announced via the ELSA-2012-0899 advisory.
Description:Summary:
The remote host is missing an update for the 'openldap' package(s) announced via the ELSA-2012-0899 advisory.

Vulnerability Insight:
[2.4.23-26]
- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)
- fix: memory leak: def_urlpre is not freed (#816168)
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-25]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-24]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
- fix: memberof overlay on the frontend database causes server segfault (#730745)

[2.4.23-23]
- security fix: CVE-2012-1164: assertion failure by processing search queries
requesting only attributes for particular entry (#813162)

[2.4.23-22]
- fix: libraries leak memory when following referrals (#807363)

[2.4.23-21]
- fix: ldapsearch crashes with invalid parameters (#743781)
- fix: replication (syncrepl) with TLS causes segfault (#783445)
- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)
- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)
- fix: missing options in manual pages of client tools (#745470)
- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)
- fix: slapd segfaults when certificate key cannot be loaded (#796808)
- Jan Synacek + fix: overlay constraint with count option work bad with modify operation (#742163) + fix: Default SSL certificate bundle is not found by openldap library (#742023) + fix: Duplicate close() calls in OpenLDAP (#784203)

Affected Software/OS:
'openldap' package(s) on Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1164
20191211 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
https://seclists.org/bugtraq/2019/Dec/23
20191213 APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
http://seclists.org/fulldisclosure/2019/Dec/26
48372
http://secunia.com/advisories/48372
49607
http://secunia.com/advisories/49607
52404
http://www.securityfocus.com/bid/52404
GLSA-201406-36
http://security.gentoo.org/glsa/glsa-201406-36.xml
MDVSA-2012:130
http://www.mandriva.com/security/advisories?name=MDVSA-2012:130
RHSA-2012:0899
http://rhn.redhat.com/errata/RHSA-2012-0899.html
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=7143
http://www.openldap.org/software/release/changes.html
https://support.apple.com/kb/HT210788
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.