Novell Home

CVE-2010-0211

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2010-0211 at MITRE

Description

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Novell/SUSE information

Novell Bugzilla entry: 612430

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP1
  • openldap2 >= 2.4.20-0.5.1
  • openldap2-devel >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Software Development Kit 11 SP1
  • openldap2-devel >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Software Development Kit 11 SP1
  • openldap2-devel >= 2.4.20-0.5.1
  • openldap2-devel-32bit >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Software Development Kit 11 SP1
  • openldap2 >= 2.4.20-0.5.1
  • openldap2-devel >= 2.4.20-0.5.1
  • openldap2-devel-32bit >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Desktop 11 SP1
  • libldap-2_4-2 >= 2.4.20-0.5.1
  • openldap2-client >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Desktop 11 SP1
  • libldap-2_4-2 >= 2.4.20-0.5.1
  • libldap-2_4-2-32bit >= 2.4.20-0.5.1
  • openldap2-client >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Server 11 SP1
  • libldap-2_4-2 >= 2.4.20-0.5.1
  • openldap2 >= 2.4.20-0.5.1
  • openldap2-back-meta >= 2.4.20-0.5.1
  • openldap2-client >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Server 11 SP1
  • libldap-2_4-2 >= 2.4.20-0.5.1
  • libldap-2_4-2-x86 >= 2.4.20-0.5.1
  • openldap2 >= 2.4.20-0.5.1
  • openldap2-back-meta >= 2.4.20-0.5.1
  • openldap2-client >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise Server 11 SP1
  • libldap-2_4-2 >= 2.4.20-0.5.1
  • libldap-2_4-2-32bit >= 2.4.20-0.5.1
  • openldap2 >= 2.4.20-0.5.1
  • openldap2-back-meta >= 2.4.20-0.5.1
  • openldap2-client >= 2.4.20-0.5.1
sle11-sp1-sdk.x86
sled11-sp1.x86
sles11-sp1.ppc
sles11-sp1-vmware.x86-64
sles11-sp1.x86-64
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.s390x
sles11-sp1.x86
sles11-sp1.s390x
sle11-sp1-sdk.ia64
sles11-sp1.ia64
sles11-sp1-vmware.x86
sled11-sp1.x86-64
sle11-sp1-sdk.ppc
SAT Patch Nr: 2551
SUSE Linux Enterprise SDK 11 GA
  • openldap2 >= 2.4.12-7.19.1
  • openldap2-devel >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise SDK 11 GA
  • openldap2-devel >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise SDK 11 GA
  • openldap2-devel >= 2.4.12-7.19.1
  • openldap2-devel-32bit >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise SDK 11 GA
  • openldap2 >= 2.4.12-7.19.1
  • openldap2-devel >= 2.4.12-7.19.1
  • openldap2-devel-32bit >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise Desktop 11 GA
  • libldap-2_4-2 >= 2.4.12-7.19.1
  • openldap2-client >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise Desktop 11 GA
  • libldap-2_4-2 >= 2.4.12-7.19.1
  • libldap-2_4-2-32bit >= 2.4.12-7.19.1
  • openldap2-client >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise Server 11 GA
  • libldap-2_4-2 >= 2.4.12-7.19.1
  • openldap2 >= 2.4.12-7.19.1
  • openldap2-back-meta >= 2.4.12-7.19.1
  • openldap2-client >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise Server 11 GA
  • libldap-2_4-2 >= 2.4.12-7.19.1
  • libldap-2_4-2-x86 >= 2.4.12-7.19.1
  • openldap2 >= 2.4.12-7.19.1
  • openldap2-back-meta >= 2.4.12-7.19.1
  • openldap2-client >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
SUSE Linux Enterprise Server 11 GA
  • libldap-2_4-2 >= 2.4.12-7.19.1
  • libldap-2_4-2-32bit >= 2.4.12-7.19.1
  • openldap2 >= 2.4.12-7.19.1
  • openldap2-back-meta >= 2.4.12-7.19.1
  • openldap2-client >= 2.4.12-7.19.1
sle11-sdk.ia64
sles11.ia64
sle11-sdk.x86
sles11.x86-64
sles11.x86
sle11-sdk.s390x
sles11.s390x
sle11-sdk.ppc
sled11.x86-64
sles11.ppc
sle11-sdk.x86-64
sled11.x86
SAT Patch Nr: 2552
Open Enterprise Server
  • openldap2 >= 2.2.24-4.33
  • openldap2-back-ldap >= 2.2.24-4.33
  • openldap2-back-meta >= 2.2.24-4.33
  • openldap2-back-monitor >= 2.2.24-4.33
  • openldap2-back-perl >= 2.2.24-4.33
  • openldap2-client >= 2.2.24-4.33
  • openldap2-devel >= 2.2.24-4.33
core9.ia64
sles9-oes.x86
core9.x86-64
core9.ppc
core9.x86
core9.s390
core9.s390x
sles9-nlpos.x86
YOU Patch Nr: 12624
openSUSE 11.1
  • openldap2-client-debuginfo >= 2.4.12-5.6.1
  • openldap2-client-debugsource >= 2.4.12-5.6.1
  • openldap2-debuginfo >= 2.4.12-5.6.1
  • openldap2-debugsource >= 2.4.12-5.6.1
openSUSE 11.1
  • libldap-2_4-2 >= 2.4.12-5.6.1
  • libldap-2_4-2-32bit >= 2.4.12-5.6.1
  • libldap-2_4-2-64bit >= 2.4.12-5.6.1
  • openldap2 >= 2.4.12-5.6.1
  • openldap2-back-meta >= 2.4.12-5.6.1
  • openldap2-back-perl >= 2.4.12-5.6.1
  • openldap2-client >= 2.4.12-5.6.1
  • openldap2-devel >= 2.4.12-5.6.1
  • openldap2-devel-32bit >= 2.4.12-5.6.1
  • openldap2-devel-64bit >= 2.4.12-5.6.1
openSUSE 11.0
  • openldap2-client-debuginfo >= 2.4.9-7.8
  • openldap2-client-debugsource >= 2.4.9-7.8
  • openldap2-debuginfo >= 2.4.9-7.8
  • openldap2-debugsource >= 2.4.9-7.8
openSUSE 11.0
  • openldap2 >= 2.4.9-7.8
  • openldap2-back-meta >= 2.4.9-7.8
  • openldap2-back-perl >= 2.4.9-7.8
  • openldap2-client >= 2.4.9-7.8
  • openldap2-client-32bit >= 2.4.9-7.8
  • openldap2-client-64bit >= 2.4.9-7.8
  • openldap2-devel >= 2.4.9-7.8
  • openldap2-devel-32bit >= 2.4.9-7.8
  • openldap2-devel-64bit >= 2.4.9-7.8
SUSE CORE 9 for AMD64 and Intel EM64T
  • openldap2 >= 2.2.24-4.35
  • openldap2-back-ldap >= 2.2.24-4.35
  • openldap2-back-meta >= 2.2.24-4.35
  • openldap2-back-monitor >= 2.2.24-4.35
  • openldap2-back-perl >= 2.2.24-4.35
  • openldap2-client >= 2.2.24-4.35
  • openldap2-client-32bit >= 9-201106301648
  • openldap2-devel >= 2.2.24-4.35
  • openldap2-devel-32bit >= 9-201106301648
Builds
YOU Patch Nr: 12783
SUSE Linux Enterprise Desktop 10 SP3 for x86
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-client-32bit >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
  • openldap2-devel-32bit >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
SUSE Linux Enterprise Server for SAP 10 SP3
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-back-meta >= 2.3.32-0.37.1
  • openldap2-back-perl >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-client-32bit >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
  • openldap2-devel-32bit >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise SDK 10 SP3
  • openldap2-back-meta >= 2.3.32-0.37.1
  • openldap2-back-perl >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise Server 10 SP3
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-back-meta >= 2.3.32-0.37.1
  • openldap2-back-perl >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise Server 10 SP3
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-back-meta >= 2.3.32-0.37.1
  • openldap2-back-perl >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-client-x86 >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
SUSE Linux Enterprise Server 10 SP3
  • openldap2 >= 2.3.32-0.37.1
  • openldap2-back-meta >= 2.3.32-0.37.1
  • openldap2-back-perl >= 2.3.32-0.37.1
  • openldap2-client >= 2.3.32-0.37.1
  • openldap2-client-64bit >= 2.3.32-0.37.1
  • openldap2-devel >= 2.3.32-0.37.1
  • openldap2-devel-64bit >= 2.3.32-0.37.1
sle10-sp3-sdk.ppc
sles10-sp3.x86
sles10-sp3.ia64
sles10-sp3.x86-64
sles10-sp3.ppc
sles10-sp3-debuginfo.x86
sle10-sp3-sdk.s390x
sle10-sp3-sdk.x86
sled10-sp3.x86-64
sles10-sp3-debuginfo.ia64
sle10-sp3-sdk.x86-64
sles10-sp3-debuginfo.x86-64
sled10-sp3.x86
sles10-sp3-debuginfo.s390x
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sles10-sp3-debuginfo.ppc
ZYPP Patch Nr: 7074
openSUSE 11.2
  • libldap-2_4-2-debuginfo >= 2.4.17-5.4.1
  • libldap-2_4-2-debuginfo-32bit >= 2.4.17-5.4.1
  • openldap2-back-meta-debuginfo >= 2.4.17-5.4.1
  • openldap2-back-perl-debuginfo >= 2.4.17-5.4.1
  • openldap2-client-debuginfo >= 2.4.17-5.4.1
  • openldap2-client-debugsource >= 2.4.17-5.4.1
  • openldap2-debuginfo >= 2.4.17-5.4.1
  • openldap2-debugsource >= 2.4.17-5.4.1
openSUSE 11.2
  • libldap-2_4-2 >= 2.4.17-5.4.1
  • libldap-2_4-2-32bit >= 2.4.17-5.4.1
  • openldap2 >= 2.4.17-5.4.1
  • openldap2-back-meta >= 2.4.17-5.4.1
  • openldap2-back-perl >= 2.4.17-5.4.1
  • openldap2-client >= 2.4.17-5.4.1
  • openldap2-devel >= 2.4.17-5.4.1
  • openldap2-devel-32bit >= 2.4.17-5.4.1

© 2014 Novell