LWN.net Logo

openldap: man in the middle attack

Package(s):openldap CVE #(s):CVE-2009-3767
Created:November 12, 2009 Updated:July 22, 2010
Description: From the Ubuntu alert:

It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.

Alerts:
CentOS CESA-2010:0543 2010-07-21
Red Hat RHSA-2010:0543-01 2010-07-20
Red Hat RHSA-2010:0198-04 2010-03-30
Mandriva MDVSA-2010:026 2010-01-26
Debian DSA-1943 2009-12-02
Fedora FEDORA-2010-0752 2010-01-19
Ubuntu USN-858-1 2009-11-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds