Updated openldap package fixes security vulnerability
Publication date: 15 Sep 2015Modification date: 15 Sep 2015
Type: security
Affected Mageia releases : 4 , 5
CVE: CVE-2015-6908
Description
By sending a crafted packet, an attacker can cause the OpenLDAP daemon to crash with a SIGABRT. This is due to an assert() call in the ber_get_next() method in a/libraries/liblber/io.c that is hit when decoding tampered BER data (CVE-2015-6908)
References
SRPMS
5/core
- openldap-2.4.40-3.1.mga5
4/core
- openldap-2.4.38-1.5.mga4