SUSE-SA:2006:072: openldap2-client

High Nessus Plugin ID 24449


The remote host is missing a vendor-supplied security patch


The remote host is missing the patch for the advisory SUSE-SA:2006:072 (openldap2-client).

OpenLDAP libldap's strval2strlen() function contained a bug when processing the authcid string of certain Bind Requests, which could allow attackers to cause an affected application (especially the OpenLDAP Server) to crash.

This is tracked by the Mitre CVE ID CVE-2006-5779.


Plugin Details

Severity: High

ID: 24449

File Name: suse_SA_2006_072.nasl

Version: $Revision: 1.5 $

Agent: unix

Published: 2007/02/18

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list