OpenLDAP ber_get_next Denial of Service Vulnerability (CVE-2015-6908)
OpenLDAP ber_get_next Denial of Service Vulnerability (CVE-2015-6908)
Release date:
Updated on:
Affected Systems:
OpenLDAP OpenLDAP <= 2.4.42
Description:
CVE (CAN) ID: CVE-2015-6908
OpenLDAP is an open-source Lightweight Directory Access Protocol (LDAP) implementation.
In OpenLDAP 2.4.42 and earlier versions, the ber_get_next function in libraries/liblber/io. c has a security vulnerability. Remote attackers can exploit this vulnerability to cause denial of service (DoS) by constructing the BER data.
<* Source: Denis Andzakovic
*>
Suggestion:
Vendor patch:
OpenLDAP
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.openldap.org/its/index.cgi/Software%20Bugs? Id = 8240
Http://www.openldap.org/devel/gitweb.cgi? P = openldap. git; a = commit; h = 6fe51a9ab04fd28bbc171da3cf12f1c1040d6629
Liferay Portal configuration uses Oracle and OpenLDAP
Install OpenLDAP on CentOS 6.5 and configure LDAP for user logon
Install and configure OpenLDAP in RHEL7
Deployment steps of OpenLDAP server in Ubuntu
Axigen + OpenLDAP + BerkeleyDB + ejabberd multi-domain + WeChat chat detailed configuration
Deploy OpenLDAP authentication in CentOS
Install OpenLDAP server in CentOS Linux
OpenLDAP details: click here
OpenLDAP: click here
This article permanently updates the link address: