CVE-2007-6698
Published: 1 February 2008
The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.
Notes
Author | Note |
---|---|
jdstrand | openldap2 source package does not ship slapd |
Priority
Status
Package | Release | Status |
---|---|---|
openldap2 Launchpad, Ubuntu, Debian |
dapper |
Ignored
|
edgy |
Ignored
|
|
feisty |
Ignored
|
|
gutsy |
Ignored
|
|
upstream |
Needs triage
|
|
openldap2.2 Launchpad, Ubuntu, Debian |
dapper |
Released
(2.2.26-5ubuntu2.6)
|
edgy |
Released
(2.2.26-5ubuntu3.3)
|
|
feisty |
Does not exist
|
|
gutsy |
Does not exist
|
|
upstream |
Needs triage
|
|
openldap2.3 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
edgy |
Does not exist
|
|
feisty |
Released
(2.3.30-2ubuntu0.2)
|
|
gutsy |
Released
(2.3.35-1ubuntu0.2)
|
|
upstream |
Needs triage
|
|
Patches: vendor: https://rhn.redhat.com/errata/RHSA-2008-0110.html |