PT-2003-2532 · Openldap · Openldap2+8

Published

1970-01-01

·

Updated

2008-09-10

·

CVE-2002-1508

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions 2.2.0 and earlier OpenLDAP2 versions 2.2.0 and earlier openldap-devel versions 2.0.27 openldap-clients versions 1.2.13 and 2.0.27 openldap-servers versions 1.2.13 and 2.0.27 libldap2 (affected versions not specified) ldap-gateways (affected versions not specified) openldap12-1.2.13 openldap-1.2.13 openldap-2.0.27
Description The issue involves multiple vulnerabilities in OpenLDAP packages, which can lead to the disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability in slapd of OpenLDAP2 allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.
Recommendations For OpenLDAP versions 2.2.0 and earlier, update to a version later than 2.2.0. For openldap-devel version 2.0.27, update to a version later than 2.0.27. For openldap-clients versions 1.2.13 and 2.0.27, update to versions later than 1.2.13 and 2.0.27 respectively. For openldap-servers versions 1.2.13 and 2.0.27, update to versions later than 1.2.13 and 2.0.27 respectively. For libldap2, ldap-gateways, openldap12-1.2.13, openldap-1.2.13, and openldap-2.0.27, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03158
BDU:2015-03159
BDU:2015-08174
BDU:2015-08175
BDU:2015-08176
BDU:2015-08177
BDU:2015-08178
BDU:2015-08179
BDU:2015-08180
BDU:2015-08181
BDU:2015-08182
CVE-2002-1508
DSA-227

Affected Products

Openldap
Openldap2
Ldap-Gateways
Libldap2
Openldap-Clients
Openldap-Devel
Openldap-Servers
Openldap12
Slapd