SciLinux: CVE-2006-4600 openldap SL3,x i386/x86_64
Summary
Date: Fri, 15 Jun 2007 17:27:52 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for openldap on SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Low: openldap security and bug-fix updateIssue date: 2007-06-11CVE Names: CVE-2006-4600A flaw was found in the way OpenLDAP handled selfwrite access. Users withselfwrite access were able to modify the distinguished name of any user.Users with selfwrite access should only be able to modify their owndistinguished name. (CVE-2006-4600)A memory leak bug was found in OpenLDAP's ldap_start_tls_s() function. Anapplication using this function could result in an Out Of Memory (OOM)condition, crashing the application.SL 3.0.x SRPMS: openldap-2.0.27-23.src.rpm i386: openldap-2.0.27-23.i386.rpm openldap-clients-2.0.27-23.i386.rpm openldap-devel-2.0.27-23.i386.rpm openldap-servers-2.0.27-23.i386.rpm x86_64: openldap-2.0.27-23.i386.rpm openldap-2.0.27-23.x86_64.rpm openldap-clients-2.0.27-23.x86_64.rpm openldap-devel-2.0.27-23.x86_64.rpm openldap-servers-2.0.27-23.x86_64.rpm-Connie Sieh-Troy Dawson