OpenLDAP: Multiple vulnerabilities — GLSA 201406-36

Multiple vulnerabilities were found in OpenLDAP, allowing for Denial of Service or a man-in-the-middle attack.

Affected packages

net-nds/openldap on all architectures
Affected versions < 2.4.35
Unaffected versions >= 2.4.35

Background

OpenLDAP is an LDAP suite of application and development tools.

Description

Multiple vulnerabilities have been discovered in OpenLDAP. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker might employ a specially crafted certificate to conduct man-in-the-middle attacks on SSL connections made using OpenLDAP, bypass security restrictions or cause a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All OpenLDAP users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-nds/openldap-2.4.35"
 

References

Release date
June 30, 2014

Latest revision
June 30, 2014: 1

Severity
normal

Exploitable
remote

Bugzilla entries