Description
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
Affected products
- Debian / debian_linux2.2 – 2.2
- mandrakesoft / mandrake_linux7.1 – 7.1
- mandrakesoft / mandrake_linux7.2 – 7.2
- mandrakesoft / mandrake_linux8.0 – 8.0
- mandrakesoft / mandrake_linux_corporate_server1.0.1 – 1.0.1
- mandrakesoft / mandrake_single_network_firewall7.2 – 7.2
- openldap / openldap1.1.1 – 1.1.1
- openldap / openldap1.1.2 – 1.1.2
- openldap / openldap1.1.3 – 1.1.3
- openldap / openldap1.1.4 – 1.1.4
- openldap / openldap1.2 – 1.2
- openldap / openldap1.2.1 – 1.2.1
- openldap / openldap1.2.2 – 1.2.2
- openldap / openldap1.2.3 – 1.2.3
- openldap / openldap1.2.4 – 1.2.4
- openldap / openldap1.2.5 – 1.2.5
- openldap / openldap1.2.6 – 1.2.6
- openldap / openldap1.2.7 – 1.2.7
- openldap / openldap1.2.8 – 1.2.8
- openldap / openldap1.2.10 – 1.2.10
- openldap / openldap1.2.11 – 1.2.11
- openldap / openldap1.2.12 – 1.2.12
- openldap / openldap2.0 – 2.0
- openldap / openldap2.0.1 – 2.0.1
- openldap / openldap2.0.2 – 2.0.2
- openldap / openldap2.0.3 – 2.0.3
- openldap / openldap2.0.4 – 2.0.4
- openldap / openldap2.0.5 – 2.0.5
- openldap / openldap2.0.6 – 2.0.6
- openldap / openldap2.0.7 – 2.0.7
- openldap / openldap1.2.9 – 1.2.9
- openldap / openldap1.0 – 1.0
- openldap / openldap1.0.1 – 1.0.1
- openldap / openldap1.0.2 – 1.0.2
- openldap / openldap1.0.3 – 1.0.3
- openldap / openldap1.1 – 1.1
- RedHat / linux6.2 – 6.2
- RedHat / linux7.0 – 7.0
- RedHat / linux7.1 – 7.1
References
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2001-18.html
- MISChttp://www.osvdb.org/1905
- MISChttp://www.redhat.com/support/errata/RHSA-2001-098.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2001/dsa-068
- MISChttp://www.linux-mandrake.com/en/security/2001/MDKSA-2001-069.php3
- MISChttp://www.kb.cert.org/vuls/id/935800
- MISChttp://www.securityfocus.com/bid/3049
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000417
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/6904