PT-2009-4132 · Suse · Yast2-Ldap-Server+1
Published
2009-07-05
·
Updated
2009-07-06
·
CVE-2009-1648
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
yast2-ldap-server version on SUSE Linux Enterprise Server 11
Description:
The issue concerns the YaST2 LDAP module in yast2-ldap-server, which fails to enable the firewall under specific conditions, such as during reboots that occur while online updates are being applied. This failure makes it easier for remote attackers to gain access to network services.
Recommendations:
For yast2-ldap-server on SUSE Linux Enterprise Server 11, ensure the firewall is manually enabled after reboots during online updates to prevent unauthorized access until a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Linux Enterprise Server
Yast2-Ldap-Server