MGASA-2015-0143

Source
https://advisories.mageia.org/MGASA-2015-0143.html
Import Source
https://advisories.mageia.org/MGASA-2015-0143.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0143
Related
Published
2015-04-09T22:54:46Z
Modified
2015-04-09T22:36:41Z
Summary
Updated openldap packages fix CVE-2015-1545
Details

Updated openldap packages fix security vulnerability:

The deref overlay in slapd 2.4.13 through 2.4.40 dereferences a NULL pointer when a search request includes the Deref control with an empty list of attributes to return (missing input validation). This allows a remote unauthenticated client to crash the LDAP server (CVE-2015-1545).

References
Credits

Affected packages

Mageia:4 / openldap

Package

Name
openldap
Purl
pkg:rpm/mageia/openldap?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.38-1.3.mga4

Ecosystem specific

{
    "section": "core"
}