Debian Security Advisory

DLA-309-1 openldap -- LTS security update

Date Reported:
14 Sep 2015
Affected Packages:
openldap
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 798622.
In Mitre's CVE dictionary: CVE-2015-6908.
More information:

Denis Andzakovic discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, does not properly handle BER data. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a specially crafted packet.

The Squeeze-LTS package has been prepared by Ryan Tandy.