Release date: 2012-08-02
Updated on:
Affected Systems:
Bind DynDB LDAP bind-dyndb-ldap
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54787
Cve id: CVE-2012-3429
Bind-dyndb-ldap is the LDAP driver of BIND.
When bind-dyndb-ldap escapes the DN value of the LDAP query, an error occurs in the "dns_to_ldap_dn_escape ()" function (src/ldap_convert.c, applications can crash by suspending a specified process and rendering unavailable services.
<* Source: Petr Spacek
Link: http://secunia.com/advisories/50086/
Http://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit? Id = f345805c73c294db42452ae966c48fbc36c48006
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Bind DynDB LDAP
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://fedorahosted.org/bind-dyndb-ldap/