Background Print only logo
Viestintäviraston etusivulle
Home Page | Advice | Reports | Activities |

CERT-FI:

P.O. Box 313
FI-00181 Helsinki
Phone: +358 9 6966 510
Fax: +358 9 6966 515

PGP keys

Finnish Communications Regulatory Authority (FICORA):


Itämerenkatu 3 A
P. O. Box 313
FI-00180 HELSINKI
Phone: +358 9 6966 500
Fax: +358 9 6966 410

Detailed contact information

Home Page > Reports > 2010 > CERT-FI Advisory on OpenLDAP

CERT-FI Advisory on OpenLDAP

Target - servers and server applications





Access Vector - remote
- no user interaction required
- no authentication required





Impact - potential code execution
- denial of service




Remediation - fix provided by vendor




Details

Two vulnerabilities have been found in OpenLDAP. The vulnerabilities allow an attacker to cause a denial of service or potentially to execute his own code by sending a specially modified command to an affected server. Exploiting the vulnerabilities does not require an authenticated session with the server.

CERT-FI coordinated the remediation effort of the vulnerability

Vulnerability Coordination Information and Acknowledgements

CERT-FI has coordinated the release of these vulnerabilities between the vulnerability researchers and the affected vendors. The vulnerabilities were found by Ilkka Mattila and Tuomas Salomäki with the Codenomicon LDAPv3 test suite at the Codenomicon Crash Test Party. CERT-FI would like to thank the researchers and the OpenLDAP project for co-operation in the remediation efforts.

Vendor Information

  • OpenLDAP before version 2.4.23

Remediation

Install either the latest version of OpenLDAP (http://www.openldap.org) or a fixed version of the software provided by your operating system or application vendor.

References

Contact Information

CERT-FI Vulnerability Coordination can be contacted as follows:

Email:
vulncoord@ficora.fi
Please quote the advisory reference [FICORA #383115] in the subject line

Telephone:
+358 9 6966 510
Monday - Friday 08:00 - 16:15 (EET: UTC+2)

Fax :
+358 9 6966 515

Post:
Vulnerability Coordination
FICORA/CERT-FI
P.O. Box 313
FI-00181 Helsinki
FINLAND

CERT-FI encourages those who wish to communicate via email to make use
of our PGP key. The key is available at

https://www.cert.fi/en/activities/contact/pgp-keys.html

The CERT-FI vulnerability coordination policy can be viewed at

https://www.cert.fi/en/activities/Vulncoord/vulncoord-policy.html.

Revision History

22 Jul 2010, 09:33 UTC: Published
30 Jul 2010, 08:34 UTC: Added advisory references for Mandriva and Debian
16 Aug 2010, 12:48 UTC: Added JPCERT/CC advisory
15 Nov 2010, 8:38 UTC: Added Apple advisory

Page updated 15.11.2010   Print version Print version