Bug 230269 (CVE-2008-2952)

Summary: net-nds/openldap < 2.3.43 ASN.1 BER Decoding Remote DoS Vulnerability (CVE-2008-2952)
Description Robert Buchholz (RETIRED) gentoo-dev 2008-06-30 21:26:15 UTC
Ludwig Nussel writes:
Remote unauthenticated attackers can trigger an assertion in the ASN.1 BER
decoding of openlap and crash the server:;selectid=5580

Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-07-02 19:10:53 UTC
The patch seems to be broken, see (1.121 -> 1.122)
Comment 2 Markus Ullmann (RETIRED) gentoo-dev 2008-07-07 21:25:30 UTC
looks like upstream is working on this: (email)

Please test RE23, thanks!

Only minor fixes plus the security fix.

Comment 3 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-20 16:11:56 UTC
any news here? according to $URL, 2.3.43 should be ok
Comment 4 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2008-07-20 18:50:15 UTC
security: .43 in the tree now, passed the testsuite.
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-07-20 18:53:38 UTC
(In reply to comment #4)
> security: .43 in the tree now, passed the testsuite.

Arches, please test and mark stable net-nds/openldap-2.3.43. Target Keywords: "alpha amd64 arm hppa ia64 ~mips ppc ppc64 s390 sh sparc ~sparc-fbsd x86 ~x86-fbsd"
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2008-07-21 01:57:47 UTC
Stable for HPPA.
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2008-07-21 16:07:41 UTC
ppc64 stable
Comment 8 Friedrich Oslage (RETIRED) gentoo-dev 2008-07-21 19:46:00 UTC
sparc stable
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2008-07-21 20:57:19 UTC
alpha/ia64/x86 stable
Comment 11 Tobias Scherbaum (RETIRED) gentoo-dev 2008-07-22 20:15:10 UTC
ppc stable
Comment 12 Tobias Heinlein (RETIRED) gentoo-dev 2008-08-03 20:28:35 UTC
amd64 stable
Comment 13 Tobias Heinlein (RETIRED) gentoo-dev 2008-08-03 20:29:20 UTC
Ready for vote, I vote YES.
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2008-08-05 14:53:02 UTC
Remote unauthenticated DoS -> obviously Yes.
Comment 15 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2008-08-05 20:53:18 UTC
glsa drafted
Comment 16 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2008-08-08 17:30:15 UTC
