Oval Definition:oval:org.mitre.oval:def:23794
Revision Date:2014-05-26Version:13
Title:ELSA-2014:0126: openldap security and bug fix update (Moderate)
Description:The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-4449
ELSA-2014:0126-00
Platform(s):Oracle Linux 6
Product(s):openldap
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • openldap-servers is earlier than 0:2.4.23-34.el6_5.1
  • OR openldap-servers-sql is earlier than 0:2.4.23-34.el6_5.1
  • OR openldap is earlier than 0:2.4.23-34.el6_5.1
  • OR openldap-clients is earlier than 0:2.4.23-34.el6_5.1
  • OR openldap-devel is earlier than 0:2.4.23-34.el6_5.1
  • BACK