CVE-2015-6908

Publication date 11 September 2015

Last updated 24 July 2024


Ubuntu priority

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

Status

Package Ubuntu Release Status
openldap 15.04 vivid
Fixed 2.4.31-1+nmu2ubuntu12.3
14.04 LTS trusty
Fixed 2.4.31-1+nmu2ubuntu8.2
12.04 LTS precise
Fixed 2.4.28-1.1ubuntu4.6

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
openldap

References

Related Ubuntu Security Notices (USN)

    • USN-2742-1
    • OpenLDAP vulnerabilities
    • 16 September 2015

Other references