~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-2668

  • Committer: Steve Beattie
  • Date: 2018-06-22 16:34:50 UTC
  • Revision ID: sbeattie@ubuntu.com-20180622163450-j48blbt278zn8t2y
Process cves run: triaged 3 CVEs, 10 Ignored, 5 Packages

Packages with new cves:
  exempi(1) linux(1) qemu(1) qemu-kvm(1) virtualbox(1)

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
Candidate: CVE-2017-2668
2
 
PublicDate: 2017-04-13
 
2
PublicDate: 2018-06-22
3
3
References:
4
4
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2668
5
5
 https://bugzilla.redhat.com/show_bug.cgi?id=1436575
6
6
 https://pagure.io/389-ds-base/issue/49184
7
7
 https://git.centos.org/raw/rpms!389-ds-base!/c9e5dad69e2b497f118efac56f43cc6c74b6a695/SOURCES!0072-fix-for-cve-2017-2668-simple-return-text-if-suffix-n.patch
8
8
Description:
9
 
 Remote crash via crafted LDAP messages
 
9
 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an
 
10
 invalid pointer dereference in the way LDAP bind requests are handled. A
 
11
 remote unauthenticated attacker could use this flaw to make ns-slapd crash
 
12
 via a specially crafted LDAP bind request, resulting in denial of service.
10
13
Ubuntu-Description:
11
14
Notes:
12
15
Bugs: