NASLDB: RHSA-2012-0683: bind-dyndb-ldap
General
ID: 59224
Name: RHSA-2012-0683: bind-dyndb-ldap
Summary: Check for the version of the bind-dyndb-ldap packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
An updated bind-dyndb-ldap package that fixes one security issue is now
available for Red Hat Enterprise Linux 6.
The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.
The dynamic LDAP back end is a plug-in for BIND that provides back-end
capabilities to LDAP databases. It features support for dynamic updates
and internal caching that help to reduce the load on LDAP servers.
A flaw was found in the way bind-dyndb-ldap handled LDAP query errors. If a
remote attacker were able to send DNS queries to a named server that is
configured to use bind-dyndb-ldap, they could trigger such an error with a
DNS query leveraging bind-dyndb-ldap\‘s insufficient escaping of the LDAP
base DN (distinguished name). This would result in an invalid LDAP query
that named would retry in a loop, preventing it from responding to other
DNS queries. With this update, bind-dyndb-ldap only attempts to retry one
time when an LDAP search returns an unexpected error. (CVE-2012-2134)
Red Hat would like to thank Ronald van Zantvoort for reporting this issue.
All bind-dyndb-ldap users should upgrade to this updated package, which
contains a backported patch to correct this issue. For the update to take
effect, the named service must be restarted.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2012-2134
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2012/05/22
Plugin
Version: 1.1
Filename: redhat-RHSA-2012-0683.nasl
Filesize: 3442 bytes
MD5 Hash: f085df46f60411d85d33c2599afe54a6
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













