Apple Mac OS X OpenLDAP Open Directory denial of service
| macosx-openldap-directory-dos (27480) |
Description:
Apple Mac OS X and Mac OS X Server could allow a remote attacker to launch a denial of service attack against the Open Directory server. An attacker could exploit this vulnerability by sending a specially-crafted LDAP request to cause the Open Directory server to crash.
Consequences:
Denial of Service
Remedy:
Apply the Mac OS X 10.4.7 Update, available from the Apple Web site. See References.
References:
- Apple Security-Announce Mailing List, Tue, 27 Jun 2006 13:16:56 -0700: APPLE-SA-2006-06-27 Mac OS X v10.4.7.
- Mac OS X 10.4.7 Update : About the security content of the Mac OS X 10.4.7 Update.
- Mu Security Advisory MU-200606-02: Apple Open Directory Pre-Authentication Denial of Service [MU-200606-02].
- BID-18686: Retired: Apple Mac OS X Multiple Security Vulnerabilities
- BID-18728: Apple Mac OS X OpenLDAP Denial Of Service Vulnerability
- CVE-2006-1470: OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
- OSVDB ID: 26932: Mac OS X OpenLDAP Server Malformed Request Remote DoS
- SA20877: Mac OS X Update Fixes Multiple Vulnerabilities
- SECTRACK ID: 1016396: OpenLDAP on Mac OS X Lets Remote Users Cause Denial of Service Conditions
- US-CERT VU#652196: Apple Mac OS X Open Directory server vulnerable to DoS via an invalid LDAP request
- VUPEN/ADV-2006-2566: Apple Mac OS X Multiple Command Execution and Privilege Escalation Vulnerabilities
Platforms Affected:
- Apple Mac OS X 10.4
- Apple Mac OS X 10.4.1
- Apple Mac OS X 10.4.10
- Apple Mac OS X 10.4.11
- Apple Mac OS X 10.4.2
- Apple Mac OS X 10.4.3
- Apple Mac OS X 10.4.4
- Apple Mac OS X 10.4.5
- Apple Mac OS X 10.4.6
- Apple Mac OS X Server 10.4
- Apple Mac OS X Server 10.4.1
- Apple Mac OS X Server 10.4.10
- Apple Mac OS X Server 10.4.11
- Apple Mac OS X Server 10.4.2
- Apple Mac OS X Server 10.4.3
- Apple Mac OS X Server 10.4.4
- Apple Mac OS X Server 10.4.5
- Apple Mac OS X Server 10.4.6
Reported:
Jun 27, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
