PT-2007-1078 · Openldap+1 · Openldap+1

Published

2007-01-23

·

Updated

2011-03-08

·

CVE-2007-0476

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenLDAP versions prior to 2.1.30-r10 OpenLDAP versions prior to 2.2.28-r7 OpenLDAP versions prior to 2.3.30-r2
Description: The issue affects the OpenLDAP package in Gentoo Linux and can lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited locally. The gencert.sh script does not create temporary directories in /tmp securely during emerge, allowing local users to overwrite arbitrary files via a symlink attack.
Recommendations: For versions prior to 2.1.30-r10, update to version 2.1.30-r10 or later. For versions prior to 2.2.28-r7, update to version 2.2.28-r7 or later. For versions prior to 2.3.30-r2, update to version 2.3.30-r2 or later. As a temporary workaround, consider restricting access to the gencert.sh script until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09553
CVE-2007-0476

Affected Products

Gentoo Linux
Openldap