LWN.net Logo

389-ds-base: denial of service

Package(s):389-ds-base CVE #(s):CVE-2012-0833
Created:June 20, 2012 Updated:July 10, 2012
Description: From the Red Hat advisory:

A flaw was found in the way the 389 Directory Server daemon (ns-slapd) handled access control instructions (ACIs) using certificate groups. If an LDAP user that had a certificate group defined attempted to bind to the directory server, it would cause ns-slapd to enter an infinite loop and consume an excessive amount of CPU time.

Alerts:
Red Hat RHSA-2012:0813-04 2012-06-20
Oracle ELSA-2012-0813 2012-07-02
Scientific Linux SL-389--20120709 2012-07-09
CentOS CESA-2012:0813 2012-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds