Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51498
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2002:459
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLA-2002:459.

OpenLDAP[1] is an LDAPv2 and LDAPv3 server available for several
platforms.

Thomas Fritz reported[3] a vulnerability in the ldap server which
could be exploited by remote attackers to delete attributes from an
object even if those attributes were protected by ACLs.

Authenticated users (in openldap versions 2.0.8 up to 2.0.19) could
issue a REPLACE command for an attribute where the new value is an
empty one, thus effectively removing the attribute if allowed by the
current schema, that is, if the attribute in question is not
mandatory. In versions prior to 2.0.8, anonymous users could do this
as well, regardless of ACLs protecting this attribute.

The OpenLDAP project has released[2] a new version to address this
vulnerability. OpenLDAP 1.2.x is not affected by this vulnerability,
only the specified 2.0.x releases.



Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:459
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.