PT-2009-4132 · Suse · Yast2-Ldap-Server+1

Published

2009-07-05

·

Updated

2009-07-06

·

CVE-2009-1648

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: yast2-ldap-server version on SUSE Linux Enterprise Server 11
Description: The issue concerns the YaST2 LDAP module in yast2-ldap-server, which fails to enable the firewall under specific conditions, such as during reboots that occur while online updates are being applied. This failure makes it easier for remote attackers to gain access to network services.
Recommendations: For yast2-ldap-server on SUSE Linux Enterprise Server 11, ensure the firewall is manually enabled after reboots during online updates to prevent unauthorized access until a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1648

Affected Products

Suse Linux Enterprise Server
Yast2-Ldap-Server