LWN.net Logo

redhat-ds-base: multiple vulnerabilities

Package(s):redhat-ds-base CVE #(s):CVE-2008-2930 CVE-2008-3283
Created:September 11, 2008 Updated:September 17, 2008
Description: From the Red Hat alert:

Multiple memory leaks were identified in the Directory Server. An unauthenticated remote attacker could use these flaws to trigger high memory consumption in the Directory Server, possibly causing it to crash or terminate unexpectedly when the server ran out of available memory. (CVE-2008-3283)

Ulf Weltman of Hewlett-Packard discovered a flaw in the way Directory Server handled LDAP search requests with patterns. A remote attacker with access to the LDAP service could create a search request that, when the search pattern was matched against specially crafted data records, caused Directory Server to use a large amount of CPU time. Directory Server did not impose time limits on such search requests. In this updated package, Directory Server imposes a configurable limit on the pattern-search query run time, with the default limit set to 30 seconds. (CVE-2008-2930)

Alerts:
Fedora FEDORA-2008-7891 2008-09-11
Fedora FEDORA-2008-7813 2008-09-11
Red Hat RHSA-2008:0858-01 2008-09-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds