Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-0009

Опубликовано: 07 янв. 2016
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2016-0009: libldb security update (MODERATE)

[1.1.13-3.1]

  • Resolves: rhbz#1290712 - CVE-2015-5330 libldb: samba: Remote memory read in Samba LDAP server [rhel-7.2.z]
  • Remove the patch from the previous commit, it doesn't fix a remotely eploitable issue. Add patches from upstream #11636 instead.

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

ldb-tools

1.1.13-3.el6_7.1

libldb

1.1.13-3.el6_7.1

libldb-devel

1.1.13-3.el6_7.1

pyldb

1.1.13-3.el6_7.1

pyldb-devel

1.1.13-3.el6_7.1

Oracle Linux i686

ldb-tools

1.1.13-3.el6_7.1

libldb

1.1.13-3.el6_7.1

libldb-devel

1.1.13-3.el6_7.1

pyldb

1.1.13-3.el6_7.1

pyldb-devel

1.1.13-3.el6_7.1

Oracle Linux 7

Oracle Linux x86_64

ldb-tools

1.1.20-1.el7_2.2

libldb

1.1.20-1.el7_2.2

libldb-devel

1.1.20-1.el7_2.2

pyldb

1.1.20-1.el7_2.2

pyldb-devel

1.1.20-1.el7_2.2

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 9 лет назад

Security update for ldb, samba, talloc, tdb, tevent

suse-cvrf
больше 9 лет назад

Security update for ldb, samba, talloc, tdb, tevent

suse-cvrf
больше 9 лет назад

Security update for ldb, samba, talloc, tdb, tevent

CVSS3: 7.5
ubuntu
больше 9 лет назад

ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.

redhat
больше 9 лет назад

ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.