Fedora 13 : openldap-2.4.21-10.fc13 (2010-11343)

This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

- Tue Jul 20 2010 Jan Vcelak <jvcelak at redhat.com> -
2.4.21-10

- CVE-2010-0211 openldap: modrdn processing
uninitialized pointer free (#605448)

- CVE-2010-0212 openldap: modrdn processing
IA5StringNormalize NULL pointer dereference (#605452)

- obsolete configuration file moved to
/usr/share/openldap-servers (#612602)

- Thu Jul 1 2010 Jan Zeleny <jzeleny at redhat.com> -
2.4.21-9

- another shot at previous fix

- Wed Jun 30 2010 Jan Zeleny <jzeleny at redhat.com> -
2.4.21-8

- fixed issue with owner of /usr/lib/ldap/__db.*
(#609523)

- Thu May 27 2010 Jan Zeleny <jzeleny at redhat.com> -
2.4.21-7

- updated autofs schema (#587722)

- openldap built with conectionless support (#587722)

- Fri Mar 19 2010 Jan Zeleny <jzeleny at redhat.com> -
2.4.21-6

- moved slapd to start earlier during boot sequence

- Tue Mar 16 2010 Jan Zeleny <jzeleny at redhat.com> -
2.4.21-5

- minor corrections of init script (#571235, #570057,
#573804)

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=605448
https://bugzilla.redhat.com/show_bug.cgi?id=605452
http://www.nessus.org/u?9b795586

Solution :

Update the affected openldap package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 3.9
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: Fedora Local Security Checks

Nessus Plugin ID: 48410 (fedora_2010-11343.nasl)

Bugtraq ID: 41770

CVE ID: CVE-2010-0211
CVE-2010-0212

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now