Upstream information
Description
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 612430 SUSE Security Advisories:- SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
- SUSE-SR:2010:016, published Thu, 26 Aug 2010 11:00:00 +0000
- openSUSE-SU-2010:0427-1, published Sat, 24 Jul 2010 04:08:11 +0200 (CEST)
- openSUSE-SU-2010:0546-1, published Wed, 25 Aug 2010 15:08:17 +0200 (CEST)
- openSUSE-SU-2010:0547-1, published Wed, 25 Aug 2010 15:08:20 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-sdk.x86 sled11-sp1.x86 sles11-sp1.ppc sles11-sp1-vmware.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.ia64 sles11-sp1.ia64 sles11-sp1-vmware.x86 sled11-sp1.x86-64 sle11-sp1-sdk.ppc SAT Patch Nr: 2551 |
| SUSE Linux Enterprise 11 GA DEBUGINFO |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise Desktop 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise Desktop 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| SUSE Linux Enterprise Server 11 GA |
| sle11-sdk.ia64 sles11.ia64 sle11-sdk.x86 sles11.x86-64 sles11.x86 sle11-sdk.s390x sles11.s390x sle11-sdk.ppc sled11.x86-64 sles11.ppc sle11-sdk.x86-64 sled11.x86 SAT Patch Nr: 2552 |
| Open Enterprise Server |
| core9.ia64 sles9-oes.x86 core9.x86-64 core9.ppc core9.x86 core9.s390 core9.s390x sles9-nlpos.x86 YOU Patch Nr: 12624 |
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.0 |
| |
| openSUSE 11.0 |
| |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12783 |
| SUSE Linux Enterprise Desktop 10 SP3 for x86 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise Server 10 SP3 DEBUGINFO |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise SDK 10 SP3 SUSE Linux Enterprise Server 10 SP3 SUSE Linux Enterprise Server for SAP 10 SP3 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise SDK 10 SP3 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise Server 10 SP3 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise Server 10 SP3 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| SUSE Linux Enterprise Server 10 SP3 |
| sle10-sp3-sdk.ppc sles10-sp3.x86 sles10-sp3.ia64 sles10-sp3.x86-64 sles10-sp3.ppc sles10-sp3-debuginfo.x86 sle10-sp3-sdk.s390x sle10-sp3-sdk.x86 sled10-sp3.x86-64 sles10-sp3-debuginfo.ia64 sle10-sp3-sdk.x86-64 sles10-sp3-debuginfo.x86-64 sled10-sp3.x86 sles10-sp3-debuginfo.s390x sle10-sp3-sdk.ia64 sles10-sp3.s390x sles10-sp3-debuginfo.ppc ZYPP Patch Nr: 7074 |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
|
