MGASA-2019-0280

Source
https://advisories.mageia.org/MGASA-2019-0280.html
Import Source
https://advisories.mageia.org/MGASA-2019-0280.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0280
Related
Published
2019-09-15T14:45:31Z
Modified
2019-09-15T13:49:07Z
Summary
Updated openldap packages fix security vulnerabilities
Details

Updated openldap packages fix security vulnerabilities: It was discovered that OpenLDAP incorrectly handled rootDN delegation. A database administrator could use this issue to request authorization as an identity from another database, contrary to expectations (CVE-2019-13057).

It was discovered that OpenLDAP incorrectly handled SASL authentication and session encryption. After a first SASL bind was completed, it was possible to obtain access by performing simple binds, contrary to expectations (CVE-2019-13565).

References
Credits

Affected packages

Mageia:6 / openldap

Package

Name
openldap
Purl
pkg:rpm/mageia/openldap?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.45-2.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / openldap

Package

Name
openldap
Purl
pkg:rpm/mageia/openldap?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.47-3.1.mga7

Ecosystem specific

{
    "section": "core"
}