openldap: man in the middle attack
| Package(s): | openldap | CVE #(s): | CVE-2009-3767 | ||||||||||||||||||||||||||||||||
| Created: | November 12, 2009 | Updated: | July 22, 2010 | ||||||||||||||||||||||||||||||||
| Description: | From the Ubuntu alert:
It was discovered that OpenLDAP did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
