Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2077-1] New openldap packages fix potential code execut

    From Florian Weimer@1:229/2 to All on Thu Jul 29 21:10:01 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2077-1 [email protected] http://www.debian.org/security/ Florian Weimer
    July 29, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : openldap
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-0211 CVE-2010-0212

    Two remote vulnerabilities have been discovered in OpenLDAP. The
    Common Vulnerabilities and Exposures project identifies the following
    problems:

    CVE-2010-0211

    The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does
    not check the return value of a call to the smr_normalize
    function, which allows remote attackers to cause a denial of
    service (segmentation fault) and possibly execute arbitrary code
    via a modrdn call with an RDN string containing invalid UTF-8
    sequences.

    CVE-2010-0212

    OpenLDAP 2.4.22 allows remote attackers to cause a denial of
    service (crash) via a modrdn call with a zero-length RDN
    destination string.

    For the stable distribution (lenny), this problem has been fixed in
    version 2.4.11-1+lenny2. (The missing update for the mips
    architecture will be provided soon.)

    For the unstable distribution (sid), this problem has been fixed in
    version 2.4.23-1.

    We recommend that you upgrade your openldap packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/openldap/openldap_2.4.11-1+lenny2.dsc
    Size/MD5 checksum: 1831 afe836285d70b3d51b50d06658b7cc22
    http://security.debian.org/pool/updates/main/o/openldap/openldap_2.4.11.orig.tar.gz
    Size/MD5 checksum: 4193523 d4e8669e2c9b8d981e371e97e3cf92d9
    http://security.debian.org/pool/updates/main/o/openldap/openldap_2.4.11-1+lenny2.diff.gz
    Size/MD5 checksum: 149276 e9668ba9648e3e1f306a97c6cc77d5a3

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 1018392 d18b30dd684b7582ba3f5fda7c0ec52d
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2-dbg_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 284794 3d3094d356fa97396dd53701ff8177c1
    http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 3625184 8c651f17c240c4222c26783e1333d7b4
    http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 281172 d91f060a2e0e9b3f7651913228e33a45
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 206338 7a268eec31460d56dfa4e51000a0f20e
    http://security.debian.org/pool/updates/main/o/openldap/slapd_2.4.11-1+lenny2_alpha.deb
    Size/MD5 checksum: 1534546 70ae45ec33481afbf305544bf9d70cb0

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 205426 c7fecb2287a970a5b06e1dd053413cf6
    http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 3665336 a25a01da15aed085d7476043a69c9f43
    http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 266508 be5e6b39fb89340139dbde19f09a6777
    http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 972300 a73c35b4c7f48427a8fd5fe971c1aac4
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2-dbg_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 299624 b132ed70255863a64e1eb94a5700dbf0
    http://security.debian.org/pool/updates/main/o/openldap/slapd_2.4.11-1+lenny2_amd64.deb
    Size/MD5 checksum: 1509162 0e9758a242eb928e9c5287d2801f280b

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/o/openldap/slapd_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 1413404 2ff76be2a9be2109b995d2fbb89ba776
    http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 248960 042b8f1642b8ea512ba4abdf8a60d2b3
    http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 3576526 6c38ec7d7a9e3a35e043cdb4276b837c
    http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 869398 5f75a2717d71579905ba1058d530ede0
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 179976 b69cc3f9fd1f4f09eb015e28b60d3b3a
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2-dbg_2.4.11-1+lenny2_arm.deb
    Size/MD5 checksum: 279998 0534bb7fb3fc4eaf311bf846dfb3c800

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/o/openldap/ldap-utils_2.4.11-1+lenny2_armel.deb
    Size/MD5 checksum: 244982 09dc4f6dc96aab40b399b52cdd440f49
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2-dbg_2.4.11-1+lenny2_armel.deb
    Size/MD5 checksum: 281290 ed72c73b8018e02b579af7fc8652ad5a
    http://security.debian.org/pool/updates/main/o/openldap/libldap-2.4-2_2.4.11-1+lenny2_armel.deb
    Size/MD5 checksum: 179660 3ca1f0b69016395df01441d2be719acb
    http://security.debian.org/pool/updates/main/o/openldap/libldap2-dev_2.4.11-1+lenny2_armel.deb
    Size/MD5 checksum: 863030 4382d905de1db012e3197c1b4cbd53f9
    http://security.debian.org/pool/updates/main/o/openldap/slapd-dbg_2.4.11-1+lenny2_armel.deb
    Size/MD5 checksum: 3583978 00372759861243bb13585f34bf93be4b

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Sun Jun 7 20:58:28 2026
      from Wales, Uk via Telnet
    • Michal Wronka
      Sun Jun 7 19:26:28 2026
      from Wroclaw, Poland via SSH
    • Centurion
      Sun Jun 7 16:59:51 2026
      from Berea, Ohio via Telnet
    • Furryboy
      Sun Jun 7 13:40:29 2026
      from Romania, Galati via SSH
    • Krenn
      Sun Jun 7 10:02:33 2026
      from Sydney, Nsw via Telnet
    • Spearb0y
      Sun Jun 7 07:41:05 2026
      from Massachusetts via SSH
    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 14:09:26
    Calls: 12,101
    Calls today: 1
    Files: 15,004
    Messages: 6,518,022

© >>> Magnum BBS <<<, 2026