Mageia 2020-0407: openldap security update
Summary
A vulnerability in the handling of normalization with modrdn was discovered in
OpenLDAP. An unauthenticated remote attacker can use this flaw to cause a
denial of service (slapd daemon crash) via a specially crafted packet
(CVE-2020-25692).
Also, the PID file path in the systemd service was fixed to use /run as the$
parent, rather than /var/run, eliminating warning messages in the logs.
References
- https://bugs.mageia.org/show_bug.cgi?id=26768
- https://bugs.openldap.org/show_bug.cgi?id=9370
- https://www.debian.org/security/2020/dsa-4782
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25692
Resolution
MGASA-2020-0407 - Updated openldap packages fix a security vulnerability
SRPMS
- 7/core/openldap-2.4.50-1.2.mga7