Description: | Summary: The remote host is missing an update for the 'openldap2' package(s) announced via the SUSE-SU-2015:0887-1 advisory.
Vulnerability Insight: openldap2 was updated to fix three security issues and one non-security bug.
The following vulnerabilities were fixed:
* A remote attacker could cause a denial of service (slapd crash) by unbinding immediately after a search request. (bnc#846389, CVE-2013-4449) * A remote attacker could cause a denial of service through a NULL pointer dereference and crash via an empty attribute list in a deref control in a search request. (bnc#916897, CVE-2015-1545) * A remote attacker could cause a denial of service (crash) via a crafted search query with a matched values control. (bnc#916914, CVE-2015-1546)
The following non-security bug was fixed:
* Prevent connection-0 (internal connection) from showing up in the monitor back-end. (bnc#905959)
Security Issues:
* CVE-2015-1546 <[link moved to references]> * CVE-2015-1545 <[link moved to references]> * CVE-2013-4449 <[link moved to references]>
Affected Software/OS: 'openldap2' package(s) on SUSE Linux Enterprise Desktop 11-SP3, SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 11-SP3, SUSE Linux Enterprise Server for SAP Applications 11-SP3.
Solution: Please install the updated package(s).
CVSS Score: 5.0
CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
|