SciLinux: CVE-2007-5707 openldap SL5.x i386/x86_64
Summary
Date: Tue, 13 Nov 2007 17:05:13 -0600Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for openldap on SL5.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Important: openldap security and enhancement updateIssue date: 2007-11-08CVE Names: CVE-2007-5707A flaw was found in the way OpenLDAP's slapd daemon handled malformedobjectClasses LDAP attributes. A local or remote attacker could create an LDAP request which could cause a denial of service by crashing slapd.(CVE-2007-5707)In addition, the following feature was added:* OpenLDAP client tools now have new option to configure their bind timeoutSL 5.x SRPMS:openldap-2.3.27-8.el5_1.1.src.rpm i386:openldap-2.3.27-8.el5.1.i386.rpmopenldap-clients-2.3.27-8.el5.1.i386.rpmopenldap-devel-2.3.27-8.el5.1.i386.rpmopenldap-servers-2.3.27-8.el5.1.i386.rpmopenldap-servers-sql-2.3.27-8.el5.1.i386.rpm x86_64:openldap-2.3.27-8.el5.1.i386.rpmopenldap-2.3.27-8.el5.1.x86_64.rpmopenldap-clients-2.3.27-8.el5.1.x86_64.rpmopenldap-devel-2.3.27-8.el5.1.i386.rpmopenldap-devel-2.3.27-8.el5.1.x86_64.rpmopenldap-servers-2.3.27-8.el5.1.x86_64.rpmopenldap-servers-sql-2.3.27-8.el5.1.x86_64.rpm-Connie Sieh-Troy Dawson