PT-2005-1097 · Openldap · Openldap

Publicado

2005-12-15

·

Atualizado

2008-09-05

·

CVE-2005-4442

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.2.28-r3
Description The issue concerns an untrusted search path vulnerability in OpenLDAP, which can be exploited by local users in the portage group to gain privileges. This is achieved by placing a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. Multiple vulnerabilities in the OpenLDAP package can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited locally.
Recommendations For OpenLDAP versions prior to 2.2.28-r3, update to version 2.2.28-r3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Portage temporary build directory to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09493
CVE-2005-4442

Produtos afetados

Openldap