Vulnerability Bulletins |
Múltiples vulnerabilidades en "openldap" |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto con cuenta |
System information |
|
| Property | Value |
| Affected manufacturer | GNU/Linux |
| Affected software | openldap |
Description |
|
|
Se han descubierto múltiples vulnerabilidades en openldap. Las vulnerabilidades son descritas a continuación: CVE-2011-1024: La vulnerabilidad reside en el modo en el que OpenLDAP maneja los fallos de autenticación pasados desde un OpenLDAP esclavo a un master. Un atacante podría autenticarse en el sistema mediante métodos desconocidos. CVE-2011-1025: La vulnerabilidad reside en el back end OpenLDAP de back-ndb. Un usuario remoto podría usar este fallo para acceder al directorio OpenLDAP mediante métodos desconocidos. CVE-2011-1081: La vulnerabilidad reside en el modo en el que OpenLDAP maneja las peticiones de nombres. Un usuario remoto podría ocasionar la interrupción del servidor OpenLADP mediante una petición modrdn que contenga un valor RDN vacío. |
|
Solution |
|
|
Actualización de software Red Hat (RHSA-2011:0347-1) Red Hat Enterprise Linux Desktop (v. 6) Red Hat Enterprise Linux Desktop Optional Red Hat Enterprise Linux HPC Node (v. 6) Red Hat Enterprise Linux HPC Node Optional (v. 6) Red Hat Enterprise Linux Server (v. 6) Red Hat Enterprise Linux Server Optional (v. 6) Red Hat Enterprise Linux Workstation (v. 6) Red Hat Enterprise Linux Workstation Optional (v. 6) https://rhn.redhat.com/ |
|
Standar resources |
|
| Property | Value |
| CVE |
CVE-2011-1024 CVE-2011-1025 CVE-2011-1081 |
| BID | |
Other resources |
|
|
Red Hat Security Advisory (RHSA-2011:0347-01) https://rhn.redhat.com/errata/RHSA-2011-0347.html |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2011-03-14 |






