Skip to content

Security Advisory 中(Moderate):openldapのセキュリティアップデート

アップデートID:

RHSA-2008:0110-3

タイプ:Security Advisory
重大性:中/Moderate
発行日:2008年2月21日
最終更新日:2008年2月21日
影響のある製品: RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
OVAL: https://rhn.redhat.com/errata/RHSA-2008-0110.html
CVEs (cve.mitre.org): CVE-2007-6698
CVE-2008-0658


詳細

複数のセキュリティ問題を修正したopenldapのアップデートパッケージがRed Hat Enterprise Linuxおよび5で利用可能になりました。

このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「中(Moderate)」のセキュリティ問題と評価されています。

OpenLDAPはLightweight Directory Access Protocol (LDAP) アプリケーションと開発ツールのオープンソース・スイートです。LDAPはディレクトリ・サービスへアクセスするためにプロトコル群です。

これらopenldapアップデートパッケージでは、OpenLDAPのslapdデーモンが、NOOPコントロールを含むmodifyとmodrdnリクエストをBerkeley DB (BDB)ストレージバックエンドにストアされてたオブジェクトへ送ってしまう問題を修正しています。権限を持ち認証を通過したアタッカーがこれらLDAPオブジェクトにmodifyもしくはmodrdnリクエストを送るとslapdがクラッシュする原因になります。 (CVE-2007-6698, CVE-2008-0658)

openldapのユーザは、これらの問題を解決するバックポートパッチが含まれた上記アップデートパッケージにアップグレードしてください。


解決法


このアップデートを適用する前に、ご使用のシステムに関係するリリース済みのエラータ/Errataがすべて適用されていることを確認してください。

このアップデートは、Red Hat Networkを通じて入手できます。


アップデートパッケージ

RHEL Desktop Workstation (v. 5 client)

IA-32:
openldap-devel-2.3.27-8.el5_1.3.i386.rpm     e4c893c43badef735ea45199a9aeff71
openldap-servers-2.3.27-8.el5_1.3.i386.rpm     ebe3a21e1b4efb522f1520572a30f572
openldap-servers-sql-2.3.27-8.el5_1.3.i386.rpm     dfe002fc8262f19f685e189fb685d2b0
 
x86_64:
openldap-devel-2.3.27-8.el5_1.3.i386.rpm     e4c893c43badef735ea45199a9aeff71
openldap-devel-2.3.27-8.el5_1.3.x86_64.rpm     ecf1b5de1c201ea3bbbdc98dcaba77a6
openldap-servers-2.3.27-8.el5_1.3.x86_64.rpm     486128cf4b4861d91be10e5f22c96b79
openldap-servers-sql-2.3.27-8.el5_1.3.x86_64.rpm     ea859928a73587e6c0808c130810e013
 
Red Hat Desktop (v. 4)

SRPMS:
openldap-2.2.13-8.el4_6.4.src.rpm     5b605db246ec32dd340d213dbc9faf70
 
IA-32:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-clients-2.2.13-8.el4_6.4.i386.rpm     4de0264b66c8f9147c59f324efd1a1d1
openldap-devel-2.2.13-8.el4_6.4.i386.rpm     88a83a6ab24940e37ebe6c206f7470ac
openldap-servers-2.2.13-8.el4_6.4.i386.rpm     a3ebf7af7be32afeb7a4bc51453f2a69
openldap-servers-sql-2.2.13-8.el4_6.4.i386.rpm     dec0af9be5e93acdc84698dbab1ddc39
 
x86_64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.x86_64.rpm     0d8b831af08be171b1ea728913878233
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.x86_64.rpm     59148c19f6e21a87e279e2d2318fa2df
openldap-clients-2.2.13-8.el4_6.4.x86_64.rpm     a2798f71a60f9f0b3a7b7a55ae449707
openldap-devel-2.2.13-8.el4_6.4.x86_64.rpm     4c0b4f5e6225420c8fdda71a68079dad
openldap-servers-2.2.13-8.el4_6.4.x86_64.rpm     789df4107dfc40f48d28d21d19448db1
openldap-servers-sql-2.2.13-8.el4_6.4.x86_64.rpm     0b491d588c88968de4c8a287ea3019e1
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
openldap-2.3.27-8.el5_1.3.src.rpm     487687df75bb8dd61e880b71aae725a5
 
IA-32:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.i386.rpm     e9ecad70ee9a83b99bdd0a96bbd43690
openldap-2.3.27-8.el5_1.3.i386.rpm     2c6527e18f3722be01853192d5f9d2d4
openldap-clients-2.3.27-8.el5_1.3.i386.rpm     b57f2705ab5d7a341a255e8707413140
openldap-devel-2.3.27-8.el5_1.3.i386.rpm     e4c893c43badef735ea45199a9aeff71
openldap-servers-2.3.27-8.el5_1.3.i386.rpm     ebe3a21e1b4efb522f1520572a30f572
openldap-servers-sql-2.3.27-8.el5_1.3.i386.rpm     dfe002fc8262f19f685e189fb685d2b0
 
IA-64:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.i386.rpm     e9ecad70ee9a83b99bdd0a96bbd43690
compat-openldap-2.3.27_2.2.29-8.el5_1.3.ia64.rpm     6fcfd2f1183e9ecf4ddc553db8a8a82d
openldap-2.3.27-8.el5_1.3.i386.rpm     2c6527e18f3722be01853192d5f9d2d4
openldap-2.3.27-8.el5_1.3.ia64.rpm     5f4a08af1ac9abc6dcb41106dc244323
openldap-clients-2.3.27-8.el5_1.3.ia64.rpm     ac337bfa915bfea63dcea8d2993ec629
openldap-devel-2.3.27-8.el5_1.3.ia64.rpm     d6c0c5e62f92767ed86fb18bb4958bfd
openldap-servers-2.3.27-8.el5_1.3.ia64.rpm     93156f66be973facf18f9fcfabd1b115
openldap-servers-sql-2.3.27-8.el5_1.3.ia64.rpm     e4f862a52a10c8bf87cbf960ba220f3f
 
PPC:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.ppc.rpm     e0a0781e02bc8815e990526185f06035
compat-openldap-2.3.27_2.2.29-8.el5_1.3.ppc64.rpm     dcab149f2a1a95e9f7a0ab5098280e76
openldap-2.3.27-8.el5_1.3.ppc.rpm     e9fb9f2bc8c36ec769dc633a65b43a5c
openldap-2.3.27-8.el5_1.3.ppc64.rpm     bd8329e8696c83c0322e40f36a00751c
openldap-clients-2.3.27-8.el5_1.3.ppc.rpm     1f87fa560202ea28efb411138cbdfb91
openldap-devel-2.3.27-8.el5_1.3.ppc.rpm     2f29b7a3643d2ca75e1cda69406b80d1
openldap-devel-2.3.27-8.el5_1.3.ppc64.rpm     3e6bd7d895a256d873c4700cd84113d0
openldap-servers-2.3.27-8.el5_1.3.ppc.rpm     7618007e60f0c0331b98b9347a44639c
openldap-servers-sql-2.3.27-8.el5_1.3.ppc.rpm     9e6fd0c0f4bf18b832e73f1f7a2373a8
 
s390x:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.s390.rpm     785287aa9fe72d0846d92eb0ef8d831b
compat-openldap-2.3.27_2.2.29-8.el5_1.3.s390x.rpm     259d175f99afd6a66157a7a05f8f1061
openldap-2.3.27-8.el5_1.3.s390.rpm     bd7dce077f8fa8f56779782b8b7f2984
openldap-2.3.27-8.el5_1.3.s390x.rpm     e2fee6171ab94db238a5feccb3d9fe17
openldap-clients-2.3.27-8.el5_1.3.s390x.rpm     3ba20a109e477686003519e2608557cb
openldap-devel-2.3.27-8.el5_1.3.s390.rpm     36754398383e051e8cd11a0694f3f417
openldap-devel-2.3.27-8.el5_1.3.s390x.rpm     ad852a5cccc6117590a76da9e01c4d3e
openldap-servers-2.3.27-8.el5_1.3.s390x.rpm     335dffca4ad5459dec30bad6b65febf0
openldap-servers-sql-2.3.27-8.el5_1.3.s390x.rpm     a671c02cf8492c68a4eefe6d025e8ed4
 
x86_64:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.i386.rpm     e9ecad70ee9a83b99bdd0a96bbd43690
compat-openldap-2.3.27_2.2.29-8.el5_1.3.x86_64.rpm     fa202d4929ec6671c131bdf4d10fe835
openldap-2.3.27-8.el5_1.3.i386.rpm     2c6527e18f3722be01853192d5f9d2d4
openldap-2.3.27-8.el5_1.3.x86_64.rpm     fe9a1938f6acb61094e6be4d8f166deb
openldap-clients-2.3.27-8.el5_1.3.x86_64.rpm     06fba9f6a78745e1f399ea44c5fa362a
openldap-devel-2.3.27-8.el5_1.3.i386.rpm     e4c893c43badef735ea45199a9aeff71
openldap-devel-2.3.27-8.el5_1.3.x86_64.rpm     ecf1b5de1c201ea3bbbdc98dcaba77a6
openldap-servers-2.3.27-8.el5_1.3.x86_64.rpm     486128cf4b4861d91be10e5f22c96b79
openldap-servers-sql-2.3.27-8.el5_1.3.x86_64.rpm     ea859928a73587e6c0808c130810e013
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
openldap-2.2.13-8.el4_6.4.src.rpm     5b605db246ec32dd340d213dbc9faf70
 
IA-32:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-clients-2.2.13-8.el4_6.4.i386.rpm     4de0264b66c8f9147c59f324efd1a1d1
openldap-devel-2.2.13-8.el4_6.4.i386.rpm     88a83a6ab24940e37ebe6c206f7470ac
openldap-servers-2.2.13-8.el4_6.4.i386.rpm     a3ebf7af7be32afeb7a4bc51453f2a69
openldap-servers-sql-2.2.13-8.el4_6.4.i386.rpm     dec0af9be5e93acdc84698dbab1ddc39
 
IA-64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.ia64.rpm     5ae3ac91703077c488bf8d6e5c54e58d
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.ia64.rpm     c27a6f1c4213aecf4acaccc11c5f55c6
openldap-clients-2.2.13-8.el4_6.4.ia64.rpm     a327d041a2fd5b42f8a13221a03ed85c
openldap-devel-2.2.13-8.el4_6.4.ia64.rpm     d7147b7108014711cd3e139b79c84c98
openldap-servers-2.2.13-8.el4_6.4.ia64.rpm     15c6a0f5e719c79e9b460389bb92aa1d
openldap-servers-sql-2.2.13-8.el4_6.4.ia64.rpm     e86bc8d53159e9a1a4bbb80cf436e924
 
PPC:
compat-openldap-2.1.30-8.el4_6.4.ppc.rpm     b8456ac1ffcfc16368b29844a1a03160
compat-openldap-2.1.30-8.el4_6.4.ppc64.rpm     6ac52502318427499161619c03d64f18
openldap-2.2.13-8.el4_6.4.ppc.rpm     55c8f3e3ce5034b9e7e28d7f5fd65532
openldap-2.2.13-8.el4_6.4.ppc64.rpm     7269bf23e132aa6d3b7647b63e805785
openldap-clients-2.2.13-8.el4_6.4.ppc.rpm     5b1c6873e91275ca8af360ebc12aef9c
openldap-devel-2.2.13-8.el4_6.4.ppc.rpm     5c5fa6bc08aea60b5ebeb94171344d6e
openldap-servers-2.2.13-8.el4_6.4.ppc.rpm     04acb87223ad8b5e2009f28c2aa80a1a
openldap-servers-sql-2.2.13-8.el4_6.4.ppc.rpm     b52e755162856aace7b1ae2d684346c9
 
s390:
compat-openldap-2.1.30-8.el4_6.4.s390.rpm     f050d9008e4d6e5ef88c01593f36522a
openldap-2.2.13-8.el4_6.4.s390.rpm     7ff5aad64ad8289afd9abf90d7bf32b7
openldap-clients-2.2.13-8.el4_6.4.s390.rpm     fadbed3f9e8ed7f1510e6220d341356f
openldap-devel-2.2.13-8.el4_6.4.s390.rpm     f26500e82b743a8ef99bfb39af982419
openldap-servers-2.2.13-8.el4_6.4.s390.rpm     29b710d82b9f0a0a7946b3a7ecf2d1e9
openldap-servers-sql-2.2.13-8.el4_6.4.s390.rpm     93f17e8bf5cd6011fc890cdb4ebca533
 
s390x:
compat-openldap-2.1.30-8.el4_6.4.s390.rpm     f050d9008e4d6e5ef88c01593f36522a
compat-openldap-2.1.30-8.el4_6.4.s390x.rpm     dd807a2b74cbdb5cdc81bb7ce0bda276
openldap-2.2.13-8.el4_6.4.s390.rpm     7ff5aad64ad8289afd9abf90d7bf32b7
openldap-2.2.13-8.el4_6.4.s390x.rpm     b9e1fe06016288c98e8f124b40d9e4a6
openldap-clients-2.2.13-8.el4_6.4.s390x.rpm     ee68614bfba2e1a3af3f0cb1f5cfa8eb
openldap-devel-2.2.13-8.el4_6.4.s390x.rpm     71061456c2cd43d43fa98b32b71f9c87
openldap-servers-2.2.13-8.el4_6.4.s390x.rpm     863c83224afd0d2b72d78097b6b33a25
openldap-servers-sql-2.2.13-8.el4_6.4.s390x.rpm     49f8e344348d13dd630d668c46c3981b
 
x86_64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.x86_64.rpm     0d8b831af08be171b1ea728913878233
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.x86_64.rpm     59148c19f6e21a87e279e2d2318fa2df
openldap-clients-2.2.13-8.el4_6.4.x86_64.rpm     a2798f71a60f9f0b3a7b7a55ae449707
openldap-devel-2.2.13-8.el4_6.4.x86_64.rpm     4c0b4f5e6225420c8fdda71a68079dad
openldap-servers-2.2.13-8.el4_6.4.x86_64.rpm     789df4107dfc40f48d28d21d19448db1
openldap-servers-sql-2.2.13-8.el4_6.4.x86_64.rpm     0b491d588c88968de4c8a287ea3019e1
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
openldap-2.3.27-8.el5_1.3.src.rpm     487687df75bb8dd61e880b71aae725a5
 
IA-32:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.i386.rpm     e9ecad70ee9a83b99bdd0a96bbd43690
openldap-2.3.27-8.el5_1.3.i386.rpm     2c6527e18f3722be01853192d5f9d2d4
openldap-clients-2.3.27-8.el5_1.3.i386.rpm     b57f2705ab5d7a341a255e8707413140
 
x86_64:
compat-openldap-2.3.27_2.2.29-8.el5_1.3.i386.rpm     e9ecad70ee9a83b99bdd0a96bbd43690
compat-openldap-2.3.27_2.2.29-8.el5_1.3.x86_64.rpm     fa202d4929ec6671c131bdf4d10fe835
openldap-2.3.27-8.el5_1.3.i386.rpm     2c6527e18f3722be01853192d5f9d2d4
openldap-2.3.27-8.el5_1.3.x86_64.rpm     fe9a1938f6acb61094e6be4d8f166deb
openldap-clients-2.3.27-8.el5_1.3.x86_64.rpm     06fba9f6a78745e1f399ea44c5fa362a
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
openldap-2.2.13-8.el4_6.4.src.rpm     5b605db246ec32dd340d213dbc9faf70
 
IA-32:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-clients-2.2.13-8.el4_6.4.i386.rpm     4de0264b66c8f9147c59f324efd1a1d1
openldap-devel-2.2.13-8.el4_6.4.i386.rpm     88a83a6ab24940e37ebe6c206f7470ac
openldap-servers-2.2.13-8.el4_6.4.i386.rpm     a3ebf7af7be32afeb7a4bc51453f2a69
openldap-servers-sql-2.2.13-8.el4_6.4.i386.rpm     dec0af9be5e93acdc84698dbab1ddc39
 
IA-64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.ia64.rpm     5ae3ac91703077c488bf8d6e5c54e58d
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.ia64.rpm     c27a6f1c4213aecf4acaccc11c5f55c6
openldap-clients-2.2.13-8.el4_6.4.ia64.rpm     a327d041a2fd5b42f8a13221a03ed85c
openldap-devel-2.2.13-8.el4_6.4.ia64.rpm     d7147b7108014711cd3e139b79c84c98
openldap-servers-2.2.13-8.el4_6.4.ia64.rpm     15c6a0f5e719c79e9b460389bb92aa1d
openldap-servers-sql-2.2.13-8.el4_6.4.ia64.rpm     e86bc8d53159e9a1a4bbb80cf436e924
 
x86_64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.x86_64.rpm     0d8b831af08be171b1ea728913878233
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.x86_64.rpm     59148c19f6e21a87e279e2d2318fa2df
openldap-clients-2.2.13-8.el4_6.4.x86_64.rpm     a2798f71a60f9f0b3a7b7a55ae449707
openldap-devel-2.2.13-8.el4_6.4.x86_64.rpm     4c0b4f5e6225420c8fdda71a68079dad
openldap-servers-2.2.13-8.el4_6.4.x86_64.rpm     789df4107dfc40f48d28d21d19448db1
openldap-servers-sql-2.2.13-8.el4_6.4.x86_64.rpm     0b491d588c88968de4c8a287ea3019e1
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
openldap-2.2.13-8.el4_6.4.src.rpm     5b605db246ec32dd340d213dbc9faf70
 
IA-32:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-clients-2.2.13-8.el4_6.4.i386.rpm     4de0264b66c8f9147c59f324efd1a1d1
openldap-devel-2.2.13-8.el4_6.4.i386.rpm     88a83a6ab24940e37ebe6c206f7470ac
openldap-servers-2.2.13-8.el4_6.4.i386.rpm     a3ebf7af7be32afeb7a4bc51453f2a69
openldap-servers-sql-2.2.13-8.el4_6.4.i386.rpm     dec0af9be5e93acdc84698dbab1ddc39
 
IA-64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.ia64.rpm     5ae3ac91703077c488bf8d6e5c54e58d
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.ia64.rpm     c27a6f1c4213aecf4acaccc11c5f55c6
openldap-clients-2.2.13-8.el4_6.4.ia64.rpm     a327d041a2fd5b42f8a13221a03ed85c
openldap-devel-2.2.13-8.el4_6.4.ia64.rpm     d7147b7108014711cd3e139b79c84c98
openldap-servers-2.2.13-8.el4_6.4.ia64.rpm     15c6a0f5e719c79e9b460389bb92aa1d
openldap-servers-sql-2.2.13-8.el4_6.4.ia64.rpm     e86bc8d53159e9a1a4bbb80cf436e924
 
x86_64:
compat-openldap-2.1.30-8.el4_6.4.i386.rpm     31ae76e534e3df90935765d0e328cef9
compat-openldap-2.1.30-8.el4_6.4.x86_64.rpm     0d8b831af08be171b1ea728913878233
openldap-2.2.13-8.el4_6.4.i386.rpm     d8ea6d15d1edac14dd59a88e7de7292f
openldap-2.2.13-8.el4_6.4.x86_64.rpm     59148c19f6e21a87e279e2d2318fa2df
openldap-clients-2.2.13-8.el4_6.4.x86_64.rpm     a2798f71a60f9f0b3a7b7a55ae449707
openldap-devel-2.2.13-8.el4_6.4.x86_64.rpm     4c0b4f5e6225420c8fdda71a68079dad
openldap-servers-2.2.13-8.el4_6.4.x86_64.rpm     789df4107dfc40f48d28d21d19448db1
openldap-servers-sql-2.2.13-8.el4_6.4.x86_64.rpm     0b491d588c88968de4c8a287ea3019e1
 
(The unlinked packages above are only available from the Red Hat Network)


バグフィックス (詳細は、bugzilla/バグジラ[英語]を御覧ください。)

431203 - CVE-2007-6698 openldap: slapd crash on NOOP control operation on entry in bdb storage
432008 - CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage



キーワード


[an error occurred while processing this directive]


ここに在るパッケージはセキュリティの為、Red Hat, Inc. によって、GPG認証されています。
認証キー及び詳細は以下を御覧下さい。
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/