Login
Newsletter
Werbung

Sicherheit: Denial of Service in OpenLDAP
Aktuelle Meldungen Distributionen
Name: Denial of Service in OpenLDAP
ID: USN-4352-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 19.10, Ubuntu 20.04 LTS
Datum: Mi, 6. Mai 2020, 19:02
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12243
Applikationen: OpenLDAP

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0201918001028699795==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="TPWiFEz0UHme1Kww6hdDiaHDOWU6vtQuc"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--TPWiFEz0UHme1Kww6hdDiaHDOWU6vtQuc
Content-Type: multipart/mixed;
boundary="V5rZSEBLVjpsrFu2sGY7W97SCzEuwgpTX"

--V5rZSEBLVjpsrFu2sGY7W97SCzEuwgpTX
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4352-1
May 06, 2020

openldap vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 19.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

OpenLDAP could be made to crash if it received specially crafted network
traffic.

Software Description:
- openldap: Lightweight Directory Access Protocol

Details:

It was discovered that OpenLDAP incorrectly handled certain queries. A
remote attacker could possibly use this issue to cause OpenLDAP to consume
resources, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
slapd 2.4.49+dfsg-2ubuntu1.2

Ubuntu 19.10:
slapd 2.4.48+dfsg-1ubuntu1.1

Ubuntu 18.04 LTS:
slapd 2.4.45+dfsg-1ubuntu1.5

Ubuntu 16.04 LTS:
slapd 2.4.42+dfsg-2ubuntu3.8

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4352-1
CVE-2020-12243

Package Information:
https://launchpad.net/ubuntu/+source/openldap/2.4.49+dfsg-2ubuntu1.2
https://launchpad.net/ubuntu/+source/openldap/2.4.48+dfsg-1ubuntu1.1
https://launchpad.net/ubuntu/+source/openldap/2.4.45+dfsg-1ubuntu1.5
https://launchpad.net/ubuntu/+source/openldap/2.4.42+dfsg-2ubuntu3.8


--V5rZSEBLVjpsrFu2sGY7W97SCzEuwgpTX--

--TPWiFEz0UHme1Kww6hdDiaHDOWU6vtQuc
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl6y6t4ACgkQZWnYVadE
vpP7Mw//dUrCjiSe/n1OniPVVy6RSVRzPDBLF/OOLT+0aYPIcd2JKK7ybyqINRpU
hR0pvTYa6NeBQipFwDccDMhasvil0xcanPqdkYF/1npSqKcr1Cldt8DOFtyb82YX
rQ4jP+43OSoUu+V9h9nY8j2Z4SrrNRgE7+pRkGAYxtho6VM3uXcdMZk+5Z5iMJF/
qCVaMuwQXKus0Pz1Uy0LAHGq6MzgKWk4ps4f6sHK0h+4LPlE74tgrDwddw5tcIx8
c/YcpmAq6Sz3C7Xr5rFhuue8eVlqf4eJ6iVxmjf1BJ+CAajGZE13e19YQ0d/IN85
2ktjBoHIoIW71RQNeOiYNlaGknJ/1vgRGXQIKfpjijEM6vT0KKVGD/UUV2PU8eWU
MKDeDO5EoM+mvwXYcth6mwoZJZL+7m4jpoSkaQoBGpWUWqdWUk4ensmwk+wMj7Ml
cvUFAqqFlkC7RvGy2PZ2wcqB2CNCYsoQnlidFr6uZqhu0QsdMkdFjT6edt9DYMqB
S8Nf8IRPLe3HVknRxlyAqwI4eF0a3FpnVMse7ueHJ91d4M3jvPxIZsIC1KUy5KFx
LD/WLLU9mozUqWZxPzADI8spIbr+pa5sNia2SwJm1MtLhvY/Xym7keESg9qH7ZAT
lC6vvg9sgRBVDMdZcjsVVpyuRa4gfb9osiec6VTysancK1Lr9mQ=
=QFkv
-----END PGP SIGNATURE-----

--TPWiFEz0UHme1Kww6hdDiaHDOWU6vtQuc--


--===============0201918001028699795==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============0201918001028699795==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung