Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.881455
Category:CentOS Local Security Checks
Title:CentOS Update for compat-openldap CESA-2011:0346 centos5 x86_64
Summary:The remote host is missing an update for the 'compat-openldap'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'compat-openldap'
package(s) announced via the referenced advisory.

Vulnerability Insight:
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A flaw was found in the way OpenLDAP handled authentication failures being
passed from an OpenLDAP slave to the master. If OpenLDAP was configured
with a chain overlay and it forwarded authentication failures, OpenLDAP
would bind to the directory as an anonymous user and return success, rather
than return failure on the authenticated bind. This could allow a user on a
system that uses LDAP for authentication to log into a directory-based
account without knowing the password. (CVE-2011-1024)

This update also fixes the following bug:

* Previously, multiple concurrent connections to an OpenLDAP server could
cause the slapd service to terminate unexpectedly with an assertion error.
This update adds mutexes to protect multiple threads from accessing a
structure with a connection, and the slapd service no longer crashes.
(BZ#677611)

Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.

Affected Software/OS:
compat-openldap on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
4.6

CVSS Vector:
AV:N/AC:H/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1024
1025188
http://securitytracker.com/id?1025188
43331
http://secunia.com/advisories/43331
43708
http://secunia.com/advisories/43708
43718
http://secunia.com/advisories/43718
ADV-2011-0665
http://www.vupen.com/english/advisories/2011/0665
GLSA-201406-36
http://security.gentoo.org/glsa/glsa-201406-36.xml
MDVSA-2011:055
http://www.mandriva.com/security/advisories?name=MDVSA-2011:055
MDVSA-2011:056
http://www.mandriva.com/security/advisories?name=MDVSA-2011:056
RHSA-2011:0346
http://www.redhat.com/support/errata/RHSA-2011-0346.html
RHSA-2011:0347
http://www.redhat.com/support/errata/RHSA-2011-0347.html
USN-1100-1
http://www.ubuntu.com/usn/USN-1100-1
[openldap-announce] 20110212 OpenLDAP 2.4.24 available
http://www.openldap.org/lists/openldap-announce/201102/msg00000.html
[openldap-technical] 20100429 ppolicy master/slave issue
http://www.openldap.org/lists/openldap-technical/201004/msg00247.html
[oss-security] 20110224 CVE Request -- OpenLDAP -- two issues
http://openwall.com/lists/oss-security/2011/02/24/12
[oss-security] 20110225 Re: CVE Request -- OpenLDAP -- two issues
http://openwall.com/lists/oss-security/2011/02/25/13
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607
https://bugzilla.novell.com/show_bug.cgi?id=674985
https://bugzilla.redhat.com/show_bug.cgi?id=680466
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.