Nom du paquet
nss_ldap
Date
2008-02-25
Advisory ID
MDVSA-2008:049
Affected versions
CS4.0 x86_64 , CS4.0 i586 , 2007.0 x86_64 , 2007.0 i586

Problem description

A race condition in nss_ldap, when used in applications that use
pthread and fork after a call to nss_ldap, does not properly handle the
LDAP connection, which might cause nss_ldap to return the wrong user
data to the wrong process, giving one user access to data belonging
to another user, in some cases.

The updated package hais been patched to prevent this issue.

Updated packages

CS4.0 x86_64

 01bc19f756541e2a34943255f75a7ca4  corporate/4.0/x86_64/nss_ldap-239-3.2.20060mlcs4.x86_64.rpm 
 735c052491e2d3943be54bc93cc6fb29  corporate/4.0/SRPMS/nss_ldap-239-3.2.20060mlcs4.src.rpm

CS4.0 i586

 f862188b3f2f11aa03f656dc29bee938  corporate/4.0/i586/nss_ldap-239-3.2.20060mlcs4.i586.rpm 
 735c052491e2d3943be54bc93cc6fb29  corporate/4.0/SRPMS/nss_ldap-239-3.2.20060mlcs4.src.rpm

2007.0 x86_64

 cdcf474742cdbeeb2d8c479a17270195  2007.0/x86_64/nss_ldap-250-1.1mdv2007.0.x86_64.rpm 
 5f11443bb851c8c650c2aa1fa89743bd  2007.0/SRPMS/nss_ldap-250-1.1mdv2007.0.src.rpm

2007.0 i586

 734883fd4974f083ac6005a56438754b  2007.0/i586/nss_ldap-250-1.1mdv2007.0.i586.rpm 
 5f11443bb851c8c650c2aa1fa89743bd  2007.0/SRPMS/nss_ldap-250-1.1mdv2007.0.src.rpm

References