Updated 389-ds-base packages fix security vulnerability
Publication date: 27 Jan 2017Modification date: 27 Jan 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-2591
Description
The "attribute uniqueness" plugin did not properly NULL-terminate an array when building up its configuration if a so called 'old-style' configuration was being used. An attacker, authenticated, but possibly also unauthenticated, could possibly force the plugin to read beyond allocated memory and trigger a segfault. The crash could also possibly be triggered accidentally (CVE-2017-2591).
References
SRPMS
5/core
- 389-ds-base-1.3.4.14-1.1.mga5