|
![]() |
Problem Description |
A race condition in nss_ldap, when used in applications that use
pthread and fork after a call to nss_ldap, does not properly handle the
LDAP connection, which might cause nss_ldap to return the wrong user
data to the wrong process, giving one user access to data belonging
to another user, in some cases.
The updated package hais been patched to prevent this issue.
Updated Packages |
Mandriva Linux 2007
734883fd4974f083ac6005a56438754b 2007.0/i586/nss_ldap-250-1.1mdv2007.0.i586.rpm 5f11443bb851c8c650c2aa1fa89743bd 2007.0/SRPMS/nss_ldap-250-1.1mdv2007.0.src.rpm
Mandriva Linux 2007/X86_64
cdcf474742cdbeeb2d8c479a17270195 2007.0/x86_64/nss_ldap-250-1.1mdv2007.0.x86_64.rpm 5f11443bb851c8c650c2aa1fa89743bd 2007.0/SRPMS/nss_ldap-250-1.1mdv2007.0.src.rpm
Corporate Server 4.0
f862188b3f2f11aa03f656dc29bee938 corporate/4.0/i586/nss_ldap-239-3.2.20060mlcs4.i586.rpm 735c052491e2d3943be54bc93cc6fb29 corporate/4.0/SRPMS/nss_ldap-239-3.2.20060mlcs4.src.rpm
Corporate Server 4.0/X86_64
01bc19f756541e2a34943255f75a7ca4 corporate/4.0/x86_64/nss_ldap-239-3.2.20060mlcs4.x86_64.rpm 735c052491e2d3943be54bc93cc6fb29 corporate/4.0/SRPMS/nss_ldap-239-3.2.20060mlcs4.src.rpm
References |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5794
Upgrade |
To upgrade automatically, use MandrivaUpdate.
Verification |
Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :
rpm --checksig package.rpm
You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.
If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.