=========================================================================Ubuntu Security Notice USN-2622-1
May 26, 2015

openldap vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

OpenLDAP could be made to crash if it received specially crafted network
traffic.

Software Description:
- openldap: OpenLDAP utilities

Details:

It was discovered that OpenLDAP incorrectly handled certain search queries
that returned empty attributes. A remote attacker could use this issue to
cause OpenLDAP to assert, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-1164)

Michael Vishchers discovered that OpenLDAP improperly counted references
when the rwm overlay was used. A remote attacker could use this issue to
cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449)

It was discovered that OpenLDAP incorrectly handled certain empty attribute
lists in search requests. A remote attacker could use this issue to cause
OpenLDAP to crash, resulting in a denial of service. (CVE-2015-1545)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  slapd                           2.4.31-1+nmu2ubuntu12.1

Ubuntu 14.10:
  slapd                           2.4.31-1+nmu2ubuntu11.1

Ubuntu 14.04 LTS:
  slapd                           2.4.31-1+nmu2ubuntu8.1

Ubuntu 12.04 LTS:
  slapd                           2.4.28-1.1ubuntu4.5

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2622-1
  CVE-2012-1164, CVE-2013-4449, CVE-2015-1545

Package Information:
  https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu12.1
  https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu11.1
  https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu8.1
  https://launchpad.net/ubuntu/+source/openldap/2.4.28-1.1ubuntu4.5


Ubuntu 2622-1: OpenLDAP vulnerabilities

May 26, 2015
OpenLDAP could be made to crash if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: slapd 2.4.31-1+nmu2ubuntu12.1 Ubuntu 14.10: slapd 2.4.31-1+nmu2ubuntu11.1 Ubuntu 14.04 LTS: slapd 2.4.31-1+nmu2ubuntu8.1 Ubuntu 12.04 LTS: slapd 2.4.28-1.1ubuntu4.5 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2622-1

CVE-2012-1164, CVE-2013-4449, CVE-2015-1545

Severity
May 26, 2015

Package Information

https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu12.1 https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu11.1 https://launchpad.net/ubuntu/+source/openldap/2.4.31-1+nmu2ubuntu8.1 https://launchpad.net/ubuntu/+source/openldap/2.4.28-1.1ubuntu4.5

Related News