Debian Security Advisory
DLA-309-1 openldap -- LTS security update
- Date Reported:
- 14 Sep 2015
- Affected Packages:
- openldap
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 798622.
In Mitre's CVE dictionary: CVE-2015-6908. - More information:
-
Denis Andzakovic discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, does not properly handle BER data. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a specially crafted packet.
The Squeeze-LTS package has been prepared by Ryan Tandy.