-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch 9609dd5032a2ada02a8800965fa511b2 ## Kind: security Shortdescription.english: Security update for openldap2 Longdescription.english: Applies to Package: openldap2 Product(s): Release: 20060824 Obsoletes: none Indications Install this update if you are using the OpenLDAP server. Contraindications None. Problem description This fixes a bug in the Access Control Processing that allowed users with "selfwrite" access to an attribute to modify arbitrary values of that attribute, instead of just allowing them to add/delete their own DN to/from that attribute. Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh openldap2.rpm Hsilgne.noitpircsedgnol: Size: 2066 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> openldap2 <----- ## Filename: openldap2.rpm Label: The new OpenLDAP Server (LDAPv3) Series: i586 Size: 6527395 2116046 PatchRpmBasedOn: 2.1.4-118 2.1.4-182 2.1.4-183 2.1.4-48 2.1.4-70 2.1.4-86 PatchRpmSize: 6527395 1855259 Buildtime: 1154124441 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: Productivity/Networking/LDAP/Servers Copyright: Other License(s), see package, BSD AuthorName: AuthorAddress: Version: 2.1.4-186 StartCommand: Obsoletes: Requires: openldap2-client aaa_base fillup fileutils /usr/sbin/useradd /usr/sbin/groupadd /bin/sh /bin/sh ld-linux.so.2 libasn1.so.5 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.2) libc.so.6(GLIBC_2.2.3) libcom_err.so.1 libcrypt.so.1 libcrypt.so.1(GLIBC_2.0) libcrypto.so.0.9.6 libdb-4.0.so libdl.so.2 libgdbm.so.2 libgssapi.so.1 libkrb5.so.17 libpam.so.0 libpthread.so.0 libpthread.so.0(GLIBC_2.0) libpthread.so.0(GLIBC_2.1) libpthread.so.0(GLIBC_2.2) libresolv.so.2 libresolv.so.2(GLIBC_2.2) libroken.so.9 libsasl.so.7 libssl.so.0.9.6 rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: ldap2 Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFE7cVuqE7a6JyACsoRApPmAJ0aRDvP3FWLrFkAEZtOuFWLgi3SnQCg gu5QGC0UFV111xQ0DqzXJCCNiIY= =iPCL -----END PGP SIGNATURE-----