nss-pam-ldapd-0.7.5-18.1.AXS4
エラータID: AXSA:2013-140:01
The nss-pam-ldapd daemon, nslcd, uses a directory server to look up name service information (users, groups, etc.) on behalf of a lightweight nsswitch module.
Security issues fixed with this release:
• CVE-2013-0288
nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.
Fixed bugs:
• Fixed a misprint in the disconnect logic and added a missing return value.
• The idle time expiration test is now performed during the LDAP search operation to prevent that the connection time out on LDAP servers under heavy load.
• When accessing a large group, the nslcd daemon read a buffer provided by the glibc library. If the buffer was too small to contain the group, glibc would increase its size until the operation was successful. This returned many redundant error messages to the /var/log/message file. It has been fixed and redundant messages are not returned.
Update packages.
nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.
N/A
SRPMS
- nss-pam-ldapd-0.7.5-18.1.AXS4.src.rpm
MD5: 8259d5145fc8fdf25ff41680f243a088
SHA-256: 65bdcdbc2940bf958f83d0fb2bd17dcc3214f947ea9f0b48ad390c28b6052780
Size: 467.95 kB
Asianux Server 4 for x86
- nss-pam-ldapd-0.7.5-18.1.AXS4.i686.rpm
MD5: 22c0d7065f39237607e27af992b9b11f
SHA-256: 7c0060bfb3afc6899faa238d337094b2ec2ad5a148022a735282db9cbd96cb1f
Size: 149.43 kB
Asianux Server 4 for x86_64
- nss-pam-ldapd-0.7.5-18.1.AXS4.x86_64.rpm
MD5: a31d94299c538fa509b2535236e47379
SHA-256: ff9cdd0dd483402ca6a1764960913a37b099cd8797e8d647a513624fd4ad2a7e
Size: 150.61 kB - nss-pam-ldapd-0.7.5-18.1.AXS4.i686.rpm
MD5: 22c0d7065f39237607e27af992b9b11f
SHA-256: 7c0060bfb3afc6899faa238d337094b2ec2ad5a148022a735282db9cbd96cb1f
Size: 149.43 kB