Synopsis:    Low: openldap security and bug fix update
Issue Date:  2012-06-20
CVE Numbers: CVE-2012-1164


OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.

A denial of service flaw was found in the way the OpenLDAP server daemon
(slapd) processed certain search queries requesting only attributes and no
values. In certain configurations, a remote attacker could issue a
specially-crafted LDAP search query that, when processed by slapd, would
cause slapd to crash due to an assertion failure. (CVE-2012-1164)

These updated openldap packages include numerous bug fixes.

Users of OpenLDAP are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the OpenLDAP daemons will be restarted automatically.

SL6:
  i386
     openldap-2.4.23-26.el6.i686.rpm
     openldap-clients-2.4.23-26.el6.i686.rpm
     openldap-debuginfo-2.4.23-26.el6.i686.rpm
     openldap-devel-2.4.23-26.el6.i686.rpm
     openldap-servers-2.4.23-26.el6.i686.rpm
     openldap-servers-sql-2.4.23-26.el6.i686.rpm
  x86_64
     openldap-2.4.23-26.el6.i686.rpm
     openldap-2.4.23-26.el6.x86_64.rpm
     openldap-clients-2.4.23-26.el6.x86_64.rpm
     openldap-debuginfo-2.4.23-26.el6.i686.rpm
     openldap-debuginfo-2.4.23-26.el6.x86_64.rpm
     openldap-devel-2.4.23-26.el6.i686.rpm
     openldap-devel-2.4.23-26.el6.x86_64.rpm
     openldap-servers-2.4.23-26.el6.x86_64.rpm
     openldap-servers-sql-2.4.23-26.el6.x86_64.rpm

- Scientific Linux Development Team