MGASA-2015-0374

Source
https://advisories.mageia.org/MGASA-2015-0374.html
Import Source
https://advisories.mageia.org/MGASA-2015-0374.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0374
Related
Published
2015-09-15T14:55:06Z
Modified
2015-09-15T14:39:10Z
Summary
Updated openldap package fixes security vulnerability
Details

By sending a crafted packet, an attacker can cause the OpenLDAP daemon to crash with a SIGABRT. This is due to an assert() call in the bergetnext() method in a/libraries/liblber/io.c that is hit when decoding tampered BER data (CVE-2015-6908)

References
Credits

Affected packages

Mageia:5 / openldap

Package

Name
openldap
Purl
pkg:rpm/mageia/openldap?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.40-3.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / openldap

Package

Name
openldap
Purl
pkg:rpm/mageia/openldap?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.38-1.5.mga4

Ecosystem specific

{
    "section": "core"
}