Debian DSA-1943-1 : openldap openldap2.3 - insufficient input validation
Medium Nessus Plugin ID 44808
SynopsisThe remote Debian host is missing a security-related update.
DescriptionIt was discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
SolutionUpgrade the openldap2.3/openldap packages.
For the oldstable distribution (etch), this problem has been fixed in version 2.3.30-5+etch3 for openldap2.3.
For the stable distribution (lenny), this problem has been fixed in version 2.4.11-1+lenny1 for openldap.