Oval Definition:oval:com.redhat.rhsa:def:20170893
Revision Date:2017-04-11Version:639
Title:RHSA-2017:0893: 389-ds-base security and bug fix update (Important)
Description:389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service. (CVE-2017-2668)

    Red Hat would like to thank Joachim Jabs (F24) for reporting this issue.

    Bug Fix(es):

  • Previously, the "deref" plug-in failed to dereference attributes that use distinguished name (DN) syntax, such as "uniqueMember". With this patch, the "deref" plug-in can dereference such attributes and additionally "Name and Optional UID" syntax. As a result, the "deref" plug-in now supports any syntax. (BZ#1435365)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-2668
    RHSA-2017:0893
    RHSA-2017:0893-00
    RHSA-2017:0893-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • 389-ds-base is earlier than 0:1.2.11.15-91.el6_9
  • AND 389-ds-base is signed with Red Hat redhatrelease2 key
  • 389-ds-base-devel is earlier than 0:1.2.11.15-91.el6_9
  • AND 389-ds-base-devel is signed with Red Hat redhatrelease2 key
  • 389-ds-base-libs is earlier than 0:1.2.11.15-91.el6_9
  • AND 389-ds-base-libs is signed with Red Hat redhatrelease2 key
  • BACK