Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2009-3767 (GCVE-0-2009-3767)
Vulnerability from cvelistv5
Published
2009-10-23 19:00
Modified
2024-08-07 06:38
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-07T06:38:30.220Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "FEDORA-2010-0752", "tags": [ "vendor-advisory", "x_refsource_FEDORA", "x_transferred" ], "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "name": "[oss-security] 20090923 Re: More CVE-2009-2408 like issues", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "name": "GLSA-201406-36", "tags": [ "vendor-advisory", "x_refsource_GENTOO", "x_transferred" ], "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "name": "oval:org.mitre.oval:def:11178", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL", "x_transferred" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "name": "ADV-2010-1858", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "name": "40677", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/40677" }, { "name": "oval:org.mitre.oval:def:7274", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL", "x_transferred" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "name": "ADV-2009-3056", "tags": [ "vdb-entry", "x_refsource_VUPEN", "x_transferred" ], "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "name": "RHSA-2010:0543", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "name": "RHSA-2011:0896", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "name": "SUSE-SR:2009:016", "tags": [ "vendor-advisory", "x_refsource_SUSE", "x_transferred" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "name": "38769", "tags": [ "third-party-advisory", "x_refsource_SECUNIA", "x_transferred" ], "url": "http://secunia.com/advisories/38769" }, { "name": "APPLE-SA-2009-11-09-1", "tags": [ "vendor-advisory", "x_refsource_APPLE", "x_transferred" ], "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://support.apple.com/kb/HT3937" }, { "name": "[oss-security] 20090903 More CVE-2009-2408 like issues", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2009-09-03T00:00:00", "descriptions": [ { "lang": "en", "value": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-18T12:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "name": "FEDORA-2010-0752", "tags": [ "vendor-advisory", "x_refsource_FEDORA" ], "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "name": "[oss-security] 20090923 Re: More CVE-2009-2408 like issues", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "name": "GLSA-201406-36", "tags": [ "vendor-advisory", "x_refsource_GENTOO" ], "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "name": "oval:org.mitre.oval:def:11178", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "name": "ADV-2010-1858", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "name": "40677", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/40677" }, { "name": "oval:org.mitre.oval:def:7274", "tags": [ "vdb-entry", "signature", "x_refsource_OVAL" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "name": "ADV-2009-3056", "tags": [ "vdb-entry", "x_refsource_VUPEN" ], "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "name": "RHSA-2010:0543", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "name": "RHSA-2011:0896", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "name": "SUSE-SR:2009:016", "tags": [ "vendor-advisory", "x_refsource_SUSE" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "name": "38769", "tags": [ "third-party-advisory", "x_refsource_SECUNIA" ], "url": "http://secunia.com/advisories/38769" }, { "name": "APPLE-SA-2009-11-09-1", "tags": [ "vendor-advisory", "x_refsource_APPLE" ], "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://support.apple.com/kb/HT3937" }, { "name": "[oss-security] 20090903 More CVE-2009-2408 like issues", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-3767", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "FEDORA-2010-0752", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "name": "[oss-security] 20090923 Re: More CVE-2009-2408 like issues", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "name": "GLSA-201406-36", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "name": "oval:org.mitre.oval:def:11178", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "name": "ADV-2010-1858", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "name": "40677", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40677" }, { "name": "oval:org.mitre.oval:def:7274", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "name": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h", "refsource": "CONFIRM", "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "name": "ADV-2009-3056", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "name": "RHSA-2010:0543", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "name": "RHSA-2011:0896", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "name": "SUSE-SR:2009:016", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "name": "38769", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38769" }, { "name": "APPLE-SA-2009-11-09-1", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "name": "http://support.apple.com/kb/HT3937", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT3937" }, { "name": "[oss-security] 20090903 More CVE-2009-2408 like issues", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2009-3767", "datePublished": "2009-10-23T19:00:00", "dateReserved": "2009-10-23T00:00:00", "dateUpdated": "2024-08-07T06:38:30.220Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2009-3767\",\"sourceIdentifier\":\"cve@mitre.org\",\"published\":\"2009-10-23T19:30:00.250\",\"lastModified\":\"2025-04-09T00:30:58.490\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.\"},{\"lang\":\"es\",\"value\":\"libraries/libldap/tls_o.c en OpenLDAP, cuando se usa OpenSSL, no maneja de forma adecuada el caracter \u0027\\\\0\u0027 en un nombre de dominio, dentro del campo sujeto del Common Name (CN) en los certificados X.509, lo\\r\\nque permite a atacantes man-in-the-middle, esp\u00edar servidores SSL de su elecci\u00f3n a trav\u00e9s de certificados manipulados concedidos por Autoridades Certificadoras, esta relacionado con CVE-2009-2408.\\r\\n\"}],\"metrics\":{\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:N/C:N/I:P/A:N\",\"baseScore\":4.3,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":8.6,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-295\"}]}],\"configurations\":[{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"2.4.18\",\"matchCriteriaId\":\"1479E6E9-32C0-437A-97D0-896D354BCF46\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"DDA1CA86-1405-4C25-9BC2-5A5E6A76B911\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"10.6.2\",\"matchCriteriaId\":\"8333C974-DF5B-4098-A766-EB8D875817F5\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"B3BB5EDB-520B-4DEF-B06E-65CA13152824\"}]}]}],\"references\":[{\"url\":\"http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://secunia.com/advisories/38769\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://secunia.com/advisories/40677\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://security.gentoo.org/glsa/glsa-201406-36.xml\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://support.apple.com/kb/HT3937\",\"source\":\"cve@mitre.org\",\"tags\":[\"Broken Link\"]},{\"url\":\"http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\",\"Vendor Advisory\"]},{\"url\":\"http://www.redhat.com/support/errata/RHSA-2010-0543.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.redhat.com/support/errata/RHSA-2011-0896.html\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.vupen.com/english/advisories/2009/3056\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.vupen.com/english/advisories/2010/1858\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://secunia.com/advisories/38769\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://secunia.com/advisories/40677\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://security.gentoo.org/glsa/glsa-201406-36.xml\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://support.apple.com/kb/HT3937\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Broken Link\"]},{\"url\":\"http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Vendor Advisory\"]},{\"url\":\"http://www.redhat.com/support/errata/RHSA-2010-0543.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.redhat.com/support/errata/RHSA-2011-0896.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.vupen.com/english/advisories/2009/3056\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://www.vupen.com/english/advisories/2010/1858\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}],\"vendorComments\":[{\"organization\":\"Red Hat\",\"comment\":\"Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3767\\n\\nThis issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.\\n\\nThe Red Hat Security Response Team has rated this issue as having moderate security impact, a future openldap update may address this flaw in Red Hat Enterprise Linux 3.\",\"lastModified\":\"2010-07-20T00:00:00\"},{\"organization\":\"OpenLDAP\",\"comment\":\"OpenLDAP reported this issue and published a patch for it on 2009-07-30. The patch was included in OpenLDAP 2.4.18 which was released on 2009-09-06. The current release of OpenLDAP is available from the following location:\\n\\nhttp://www.openldap.org/software/download/\",\"lastModified\":\"2009-10-30T00:00:00\"}]}}" } }
rhsa-2010:0543
Vulnerability from csaf_redhat
Published
2010-07-20 15:56
Modified
2024-11-22 03:30
Summary
Red Hat Security Advisory: openldap security update
Notes
Topic
Updated openldap packages that fix two security issues are now available
for Red Hat Enterprise Linux 4.
The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.
Details
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.
An uninitialized pointer use flaw was discovered in the way the slapd
daemon handled modify relative distinguished name (modrdn) requests. An
authenticated user with privileges to perform modrdn operations could use
this flaw to crash the slapd daemon via specially-crafted modrdn requests.
(CVE-2010-0211)
Red Hat would like to thank CERT-FI for responsibly reporting the
CVE-2010-0211 flaw, who credit Ilkka Mattila and Tuomas Salomäki for the
discovery of the issue.
A flaw was found in the way OpenLDAP handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick applications using OpenLDAP libraries into accepting it by
mistake, allowing the attacker to perform a man-in-the-middle attack.
(CVE-2009-3767)
Users of OpenLDAP should upgrade to these updated packages, which contain
backported patches to resolve these issues. After installing this update,
the OpenLDAP daemons will be restarted automatically.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Updated openldap packages that fix two security issues are now available\nfor Red Hat Enterprise Linux 4.\n\nThe Red Hat Security Response Team has rated this update as having moderate\nsecurity impact. Common Vulnerability Scoring System (CVSS) base scores,\nwhich give detailed severity ratings, are available for each vulnerability\nfrom the CVE links in the References section.", "title": "Topic" }, { "category": "general", "text": "OpenLDAP is an open source suite of LDAP (Lightweight Directory Access\nProtocol) applications and development tools.\n\nAn uninitialized pointer use flaw was discovered in the way the slapd\ndaemon handled modify relative distinguished name (modrdn) requests. An\nauthenticated user with privileges to perform modrdn operations could use\nthis flaw to crash the slapd daemon via specially-crafted modrdn requests.\n(CVE-2010-0211)\n\nRed Hat would like to thank CERT-FI for responsibly reporting the\nCVE-2010-0211 flaw, who credit Ilkka Mattila and Tuomas Salom\u00e4ki for the\ndiscovery of the issue.\n\nA flaw was found in the way OpenLDAP handled NUL characters in the\nCommonName field of X.509 certificates. An attacker able to get a\ncarefully-crafted certificate signed by a trusted Certificate Authority\ncould trick applications using OpenLDAP libraries into accepting it by\nmistake, allowing the attacker to perform a man-in-the-middle attack.\n(CVE-2009-3767)\n\nUsers of OpenLDAP should upgrade to these updated packages, which contain\nbackported patches to resolve these issues. After installing this update,\nthe OpenLDAP daemons will be restarted automatically.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2010:0543", "url": "https://access.redhat.com/errata/RHSA-2010:0543" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "605448", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=605448" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2010/rhsa-2010_0543.json" } ], "title": "Red Hat Security Advisory: openldap security update", "tracking": { "current_release_date": "2024-11-22T03:30:00+00:00", "generator": { "date": "2024-11-22T03:30:00+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.2.1" } }, "id": "RHSA-2010:0543", "initial_release_date": "2010-07-20T15:56:00+00:00", "revision_history": [ { "date": "2010-07-20T15:56:00+00:00", "number": "1", "summary": "Initial version" }, { "date": "2010-07-20T12:34:29+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-11-22T03:30:00+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux AS version 4", "product": { "name": "Red Hat Enterprise Linux AS version 4", "product_id": "4AS", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:4::as" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux Desktop version 4", "product": { "name": "Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:4::desktop" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux ES version 4", "product": { "name": "Red Hat Enterprise Linux ES version 4", "product_id": "4ES", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:4::es" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux WS version 4", "product": { "name": "Red Hat Enterprise Linux WS version 4", "product_id": "4WS", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:4::ws" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=ia64" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=ia64" } } } ], "category": "architecture", "name": "ia64" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=i386" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=i386" } } } ], "category": "architecture", "name": "i386" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=x86_64" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.src", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.src", "product_id": "openldap-0:2.2.13-12.el4_8.3.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=src" } } } ], "category": "architecture", "name": "src" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=ppc64" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.ppc64", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc64", "product_id": "openldap-0:2.2.13-12.el4_8.3.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=ppc64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=ppc64" } } } ], "category": "architecture", "name": "ppc64" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=ppc" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=ppc" } } } ], "category": "architecture", "name": "ppc" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=s390x" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=s390x" } } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.2.13-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "openldap-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.2.13-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "product": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "product_id": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.1.30-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.2.13-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.2.13-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.2.13-12.el4_8.3?arch=s390" } } }, { "category": "product_version", "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "product": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "product_id": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.2.13-12.el4_8.3?arch=s390" } } } ], "category": "architecture", "name": "s390" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.src as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.src" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.src", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux AS version 4", "product_id": "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4AS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.src as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.src" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.src", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux Desktop version 4", "product_id": "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4Desktop" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.src as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.src" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.src", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux ES version 4", "product_id": "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4ES" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64" }, "product_reference": "compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.src as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.src" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.src", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "relates_to_product_reference": "4WS" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64 as a component of Red Hat Enterprise Linux WS version 4", "product_id": "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" }, "product_reference": "openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "relates_to_product_reference": "4WS" } ] }, "vulnerabilities": [ { "cve": "CVE-2009-3767", "discovery_date": "2009-08-21T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "530715" } ], "notes": [ { "category": "description", "text": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "title": "Vulnerability description" }, { "category": "summary", "text": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name", "title": "Vulnerability summary" }, { "category": "other", "text": "This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.\n\nThe Red Hat Security Response Team has rated this issue as having moderate security impact, a future openldap update may address this flaw in Red Hat Enterprise Linux 3.", "title": "Statement" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3767" }, { "category": "external", "summary": "RHBZ#530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3767", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3767" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767" } ], "release_date": "2009-08-10T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2010-07-20T15:56:00+00:00", "details": "Before applying this update, make sure all previously-released errata\nrelevant to your system have been applied.\n\nThis update is available via the Red Hat Network. Details on how to\nuse the Red Hat Network to apply this update are available at\nhttp://kbase.redhat.com/faq/docs/DOC-11259", "product_ids": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2010:0543" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name" }, { "acknowledgments": [ { "names": [ "CERT-FI" ] } ], "cve": "CVE-2010-0211", "discovery_date": "2010-06-13T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "605448" } ], "notes": [ { "category": "description", "text": "The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.", "title": "Vulnerability description" }, { "category": "summary", "text": "openldap: modrdn processing uninitialized pointer free", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-0211" }, { "category": "external", "summary": "RHBZ#605448", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=605448" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-0211", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0211" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-0211", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-0211" } ], "release_date": "2010-07-19T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2010-07-20T15:56:00+00:00", "details": "Before applying this update, make sure all previously-released errata\nrelevant to your system have been applied.\n\nThis update is available via the Red Hat Network. Details on how to\nuse the Red Hat Network to apply this update are available at\nhttp://kbase.redhat.com/faq/docs/DOC-11259", "product_ids": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2010:0543" } ], "scores": [ { "cvss_v2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 4.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "version": "2.0" }, "products": [ "4AS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4AS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4AS:openldap-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-0:2.2.13-12.el4_8.3.src", "4AS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4AS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4Desktop:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-0:2.2.13-12.el4_8.3.src", "4Desktop:openldap-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4Desktop:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4ES:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4ES:openldap-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-0:2.2.13-12.el4_8.3.src", "4ES:openldap-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4ES:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.i386", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ia64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.ppc64", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.s390x", "4WS:compat-openldap-0:2.1.30-12.el4_8.3.x86_64", "4WS:openldap-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-0:2.2.13-12.el4_8.3.src", "4WS:openldap-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-clients-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.ppc64", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-debuginfo-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-devel-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-0:2.2.13-12.el4_8.3.x86_64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.i386", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ia64", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.ppc", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.s390x", "4WS:openldap-servers-sql-0:2.2.13-12.el4_8.3.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "openldap: modrdn processing uninitialized pointer free" } ] }
rhsa-2011:0896
Vulnerability from csaf_redhat
Published
2011-06-22 23:14
Modified
2025-08-01 20:36
Summary
Red Hat Security Advisory: JBoss Enterprise Web Server 1.0.2 update
Notes
Topic
JBoss Enterprise Web Server 1.0.2 is now available from the Red Hat
Customer Portal for Red Hat Enterprise Linux 4, 5 and 6, Solaris, and
Microsoft Windows.
The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.
Details
JBoss Enterprise Web Server is a fully-integrated and certified set of
components for hosting Java web applications.
This is the first release of JBoss Enterprise Web Server for Red Hat
Enterprise Linux 6. For Red Hat Enterprise Linux 4 and 5, Solaris, and
Microsoft Windows, this release serves as a replacement for JBoss
Enterprise Web Server 1.0.1, and includes a number of bug fixes. Refer to
the Release Notes, linked in the References, for more information.
This update corrects security flaws in the following components:
tomcat6:
A cross-site scripting (XSS) flaw was found in the Manager application,
used for managing web applications on Apache Tomcat. If a remote attacker
could trick a user who is logged into the Manager application into visiting
a specially-crafted URL, the attacker could perform Manager application
tasks with the privileges of the logged in user. (CVE-2010-4172)
tomcat5 and tomcat6:
It was found that web applications could modify the location of the Apache
Tomcat host's work directory. As web applications deployed on Tomcat have
read and write access to this directory, a malicious web application could
use this flaw to trick Tomcat into giving it read and write access to an
arbitrary directory on the file system. (CVE-2010-3718)
A second cross-site scripting (XSS) flaw was found in the Manager
application. A malicious web application could use this flaw to conduct an
XSS attack, leading to arbitrary web script execution with the privileges
of victims who are logged into and viewing Manager application web pages.
(CVE-2011-0013)
A possible minor information leak was found in the way Apache Tomcat
generated HTTP BASIC and DIGEST authentication requests. For configurations
where a realm name was not specified and Tomcat was accessed via a proxy,
the default generated realm contained the hostname and port used by the
proxy to send requests to the Tomcat server. (CVE-2010-1157)
httpd:
A flaw was found in the way the mod_dav module of the Apache HTTP Server
handled certain requests. If a remote attacker were to send a carefully
crafted request to the server, it could cause the httpd child process to
crash. (CVE-2010-1452)
A flaw was discovered in the way the mod_proxy_http module of the Apache
HTTP Server handled the timeouts of requests forwarded by a reverse proxy
to the back-end server. In some configurations, the proxy could return
a response intended for another user under certain timeout conditions,
possibly leading to information disclosure. Note: This issue only affected
httpd running on the Windows operating system. (CVE-2010-2068)
apr:
It was found that the apr_fnmatch() function used an unconstrained
recursion when processing patterns with the '*' wildcard. An attacker could
use this flaw to cause an application using this function, which also
accepted untrusted input as a pattern for matching (such as an httpd server
using the mod_autoindex module), to exhaust all stack memory or use an
excessive amount of CPU time when performing matching. (CVE-2011-0419)
apr-util:
It was found that certain input could cause the apr-util library to
allocate more memory than intended in the apr_brigade_split_line()
function. An attacker able to provide input in small chunks to an
application using the apr-util library (such as httpd) could possibly use
this flaw to trigger high memory consumption. (CVE-2010-1623)
The following flaws were corrected in the packages for Solaris and Windows.
Updates for Red Hat Enterprise Linux can be downloaded from the Red Hat
Network.
Multiple flaws in OpenSSL, which could possibly cause a crash, code
execution, or a change of session parameters, have been corrected.
(CVE-2009-3245, CVE-2010-4180, CVE-2008-7270)
Two denial of service flaws were corrected in Expat. (CVE-2009-3560,
CVE-2009-3720)
An X.509 certificate verification flaw was corrected in OpenLDAP.
(CVE-2009-3767)
More information about these flaws is available from the CVE links in the
References.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "JBoss Enterprise Web Server 1.0.2 is now available from the Red Hat\nCustomer Portal for Red Hat Enterprise Linux 4, 5 and 6, Solaris, and\nMicrosoft Windows.\n\nThe Red Hat Security Response Team has rated this update as having moderate\nsecurity impact. Common Vulnerability Scoring System (CVSS) base scores,\nwhich give detailed severity ratings, are available for each vulnerability\nfrom the CVE links in the References section.", "title": "Topic" }, { "category": "general", "text": "JBoss Enterprise Web Server is a fully-integrated and certified set of\ncomponents for hosting Java web applications.\n\nThis is the first release of JBoss Enterprise Web Server for Red Hat\nEnterprise Linux 6. For Red Hat Enterprise Linux 4 and 5, Solaris, and\nMicrosoft Windows, this release serves as a replacement for JBoss\nEnterprise Web Server 1.0.1, and includes a number of bug fixes. Refer to\nthe Release Notes, linked in the References, for more information.\n\nThis update corrects security flaws in the following components:\n\ntomcat6:\n\nA cross-site scripting (XSS) flaw was found in the Manager application,\nused for managing web applications on Apache Tomcat. If a remote attacker\ncould trick a user who is logged into the Manager application into visiting\na specially-crafted URL, the attacker could perform Manager application\ntasks with the privileges of the logged in user. (CVE-2010-4172)\n\ntomcat5 and tomcat6:\n\nIt was found that web applications could modify the location of the Apache\nTomcat host\u0027s work directory. As web applications deployed on Tomcat have\nread and write access to this directory, a malicious web application could\nuse this flaw to trick Tomcat into giving it read and write access to an\narbitrary directory on the file system. (CVE-2010-3718)\n\nA second cross-site scripting (XSS) flaw was found in the Manager\napplication. A malicious web application could use this flaw to conduct an\nXSS attack, leading to arbitrary web script execution with the privileges\nof victims who are logged into and viewing Manager application web pages.\n(CVE-2011-0013)\n\nA possible minor information leak was found in the way Apache Tomcat\ngenerated HTTP BASIC and DIGEST authentication requests. For configurations\nwhere a realm name was not specified and Tomcat was accessed via a proxy,\nthe default generated realm contained the hostname and port used by the\nproxy to send requests to the Tomcat server. (CVE-2010-1157)\n\nhttpd:\n\nA flaw was found in the way the mod_dav module of the Apache HTTP Server\nhandled certain requests. If a remote attacker were to send a carefully\ncrafted request to the server, it could cause the httpd child process to\ncrash. (CVE-2010-1452)\n\nA flaw was discovered in the way the mod_proxy_http module of the Apache\nHTTP Server handled the timeouts of requests forwarded by a reverse proxy\nto the back-end server. In some configurations, the proxy could return\na response intended for another user under certain timeout conditions,\npossibly leading to information disclosure. Note: This issue only affected\nhttpd running on the Windows operating system. (CVE-2010-2068)\n\napr:\n\nIt was found that the apr_fnmatch() function used an unconstrained\nrecursion when processing patterns with the \u0027*\u0027 wildcard. An attacker could\nuse this flaw to cause an application using this function, which also\naccepted untrusted input as a pattern for matching (such as an httpd server\nusing the mod_autoindex module), to exhaust all stack memory or use an\nexcessive amount of CPU time when performing matching. (CVE-2011-0419)\n\napr-util:\n\nIt was found that certain input could cause the apr-util library to\nallocate more memory than intended in the apr_brigade_split_line()\nfunction. An attacker able to provide input in small chunks to an\napplication using the apr-util library (such as httpd) could possibly use\nthis flaw to trigger high memory consumption. (CVE-2010-1623)\n\nThe following flaws were corrected in the packages for Solaris and Windows.\nUpdates for Red Hat Enterprise Linux can be downloaded from the Red Hat\nNetwork.\n\nMultiple flaws in OpenSSL, which could possibly cause a crash, code\nexecution, or a change of session parameters, have been corrected.\n(CVE-2009-3245, CVE-2010-4180, CVE-2008-7270)\n\nTwo denial of service flaws were corrected in Expat. (CVE-2009-3560,\nCVE-2009-3720)\n\nAn X.509 certificate verification flaw was corrected in OpenLDAP.\n(CVE-2009-3767)\n\nMore information about these flaws is available from the CVE links in the\nReferences.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2011:0896", "url": "https://access.redhat.com/errata/RHSA-2011:0896" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "http://docs.redhat.com/docs/en-US/JBoss_Enterprise_Web_Server/1.0/html-single/Release_Notes_1.0.2/index.html", "url": "http://docs.redhat.com/docs/en-US/JBoss_Enterprise_Web_Server/1.0/html-single/Release_Notes_1.0.2/index.html" }, { "category": "external", "summary": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions\u0026product=webserver\u0026version=1.0.2", "url": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions\u0026product=webserver\u0026version=1.0.2" }, { "category": "external", "summary": "530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "531697", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=531697" }, { "category": "external", "summary": "533174", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=533174" }, { "category": "external", "summary": "570924", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=570924" }, { "category": "external", "summary": "585331", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=585331" }, { "category": "external", "summary": "618189", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=618189" }, { "category": "external", "summary": "632994", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=632994" }, { "category": "external", "summary": "640281", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=640281" }, { "category": "external", "summary": "656246", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=656246" }, { "category": "external", "summary": "659462", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=659462" }, { "category": "external", "summary": "660650", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=660650" }, { "category": "external", "summary": "675786", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=675786" }, { "category": "external", "summary": "675792", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=675792" }, { "category": "external", "summary": "703390", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=703390" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2011/rhsa-2011_0896.json" } ], "title": "Red Hat Security Advisory: JBoss Enterprise Web Server 1.0.2 update", "tracking": { "current_release_date": "2025-08-01T20:36:39+00:00", "generator": { "date": "2025-08-01T20:36:39+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.6.6" } }, "id": "RHSA-2011:0896", "initial_release_date": "2011-06-22T23:14:00+00:00", "revision_history": [ { "date": "2011-06-22T23:14:00+00:00", "number": "1", "summary": "Initial version" }, { "date": "2011-06-22T19:16:28+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2025-08-01T20:36:39+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat JBoss Web Server 1.0", "product": { "name": "Red Hat JBoss Web Server 1.0", "product_id": "Red Hat JBoss Web Server 1.0", "product_identification_helper": { "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1.0" } } } ], "category": "product_family", "name": "Red Hat JBoss Web Server" } ], "category": "vendor", "name": "Red Hat" } ] }, "vulnerabilities": [ { "cve": "CVE-2008-7270", "discovery_date": "2010-12-02T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "660650" } ], "notes": [ { "category": "description", "text": "OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.", "title": "Vulnerability description" }, { "category": "summary", "text": "openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2008-7270" }, { "category": "external", "summary": "RHBZ#660650", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=660650" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2008-7270", "url": "https://www.cve.org/CVERecord?id=CVE-2008-7270" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2008-7270", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-7270" } ], "release_date": "2010-12-02T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG downgrade-to-disabled ciphersuite attack" }, { "cve": "CVE-2009-3245", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "discovery_date": "2010-03-05T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "570924" } ], "notes": [ { "category": "description", "text": "OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.", "title": "Vulnerability description" }, { "category": "summary", "text": "openssl: missing bn_wexpand return value checks", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3245" }, { "category": "external", "summary": "RHBZ#570924", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=570924" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3245", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3245" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3245", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3245" } ], "release_date": "2010-02-23T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 7.6, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "openssl: missing bn_wexpand return value checks" }, { "cve": "CVE-2009-3560", "discovery_date": "2009-11-03T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "533174" } ], "notes": [ { "category": "description", "text": "The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.", "title": "Vulnerability description" }, { "category": "summary", "text": "expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3560" }, { "category": "external", "summary": "RHBZ#533174", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=533174" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3560", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3560" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3560", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3560" } ], "release_date": "2009-12-02T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences" }, { "cve": "CVE-2009-3720", "discovery_date": "2009-08-21T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "531697" } ], "notes": [ { "category": "description", "text": "The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.", "title": "Vulnerability description" }, { "category": "summary", "text": "expat: buffer over-read and crash on XML with malformed UTF-8 sequences", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3720" }, { "category": "external", "summary": "RHBZ#531697", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=531697" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3720", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3720" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3720", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3720" } ], "release_date": "2009-01-17T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "expat: buffer over-read and crash on XML with malformed UTF-8 sequences" }, { "cve": "CVE-2009-3767", "discovery_date": "2009-08-21T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "530715" } ], "notes": [ { "category": "description", "text": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "title": "Vulnerability description" }, { "category": "summary", "text": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name", "title": "Vulnerability summary" }, { "category": "other", "text": "This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.\n\nThe Red Hat Security Response Team has rated this issue as having moderate security impact, a future openldap update may address this flaw in Red Hat Enterprise Linux 3.", "title": "Statement" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3767" }, { "category": "external", "summary": "RHBZ#530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3767", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3767" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767" } ], "release_date": "2009-08-10T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name" }, { "cve": "CVE-2010-1157", "discovery_date": "2010-04-22T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "585331" } ], "notes": [ { "category": "description", "text": "Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server\u0027s hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.", "title": "Vulnerability description" }, { "category": "summary", "text": "tomcat: information disclosure in authentication headers", "title": "Vulnerability summary" }, { "category": "other", "text": "The risks associated with fixing this flaw are greater than the low severity security risk. We therefore have no plans to fix this flaw. The information leak can be avoided by adjusting the configuration to always specify a realm-name.", "title": "Statement" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-1157" }, { "category": "external", "summary": "RHBZ#585331", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=585331" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-1157", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1157" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-1157", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1157" } ], "release_date": "2010-04-21T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.6, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "tomcat: information disclosure in authentication headers" }, { "cve": "CVE-2010-1452", "discovery_date": "2010-07-26T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "618189" } ], "notes": [ { "category": "description", "text": "The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.", "title": "Vulnerability description" }, { "category": "summary", "text": "mod_dav: DoS (httpd child process crash) by parsing URI structure with missing path segments", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-1452" }, { "category": "external", "summary": "RHBZ#618189", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=618189" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-1452", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1452" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-1452", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1452" } ], "release_date": "2010-07-21T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "mod_dav: DoS (httpd child process crash) by parsing URI structure with missing path segments" }, { "cve": "CVE-2010-1623", "discovery_date": "2010-10-04T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "640281" } ], "notes": [ { "category": "description", "text": "Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.", "title": "Vulnerability description" }, { "category": "summary", "text": "apr-util: high memory consumption in apr_brigade_split_line()", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-1623" }, { "category": "external", "summary": "RHBZ#640281", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=640281" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-1623", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1623" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-1623", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1623" } ], "release_date": "2010-10-01T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "apr-util: high memory consumption in apr_brigade_split_line()" }, { "cve": "CVE-2010-2068", "discovery_date": "2010-09-04T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "632994" } ], "notes": [ { "category": "description", "text": "mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.", "title": "Vulnerability description" }, { "category": "summary", "text": "(mod_proxy): Sensitive response disclosure due improper handling of timeouts", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-2068" }, { "category": "external", "summary": "RHBZ#632994", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=632994" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-2068", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2068" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-2068", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2068" } ], "release_date": "2010-06-11T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "(mod_proxy): Sensitive response disclosure due improper handling of timeouts" }, { "cve": "CVE-2010-3718", "discovery_date": "2011-02-05T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "675792" } ], "notes": [ { "category": "description", "text": "Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.", "title": "Vulnerability description" }, { "category": "summary", "text": "tomcat: file permission bypass flaw", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-3718" }, { "category": "external", "summary": "RHBZ#675792", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=675792" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-3718", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3718" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-3718", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-3718" } ], "release_date": "2011-02-05T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "tomcat: file permission bypass flaw" }, { "cve": "CVE-2010-4172", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2010-11-22T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "656246" } ], "notes": [ { "category": "description", "text": "Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.", "title": "Vulnerability description" }, { "category": "summary", "text": "tomcat: cross-site-scripting vulnerability in the manager application", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-4172" }, { "category": "external", "summary": "RHBZ#656246", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=656246" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-4172", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4172" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-4172", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-4172" } ], "release_date": "2010-11-22T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "tomcat: cross-site-scripting vulnerability in the manager application" }, { "cve": "CVE-2010-4180", "discovery_date": "2010-12-02T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "659462" } ], "notes": [ { "category": "description", "text": "OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.", "title": "Vulnerability description" }, { "category": "summary", "text": "openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2010-4180" }, { "category": "external", "summary": "RHBZ#659462", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=659462" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2010-4180", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4180" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2010-4180", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-4180" } ], "release_date": "2010-12-02T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "openssl: NETSCAPE_REUSE_CIPHER_CHANGE_BUG ciphersuite downgrade attack" }, { "cve": "CVE-2011-0013", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2011-02-04T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "675786" } ], "notes": [ { "category": "description", "text": "Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.", "title": "Vulnerability description" }, { "category": "summary", "text": "tomcat: XSS vulnerability in HTML Manager interface", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2011-0013" }, { "category": "external", "summary": "RHBZ#675786", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=675786" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2011-0013", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0013" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2011-0013", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0013" } ], "release_date": "2011-01-11T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "tomcat: XSS vulnerability in HTML Manager interface" }, { "acknowledgments": [ { "names": [ "Maksymilian Arciemowicz" ] } ], "cve": "CVE-2011-0419", "discovery_date": "2011-05-10T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "703390" } ], "notes": [ { "category": "description", "text": "Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.", "title": "Vulnerability description" }, { "category": "summary", "text": "apr: unconstrained recursion in apr_fnmatch", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2011-0419" }, { "category": "external", "summary": "RHBZ#703390", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=703390" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2011-0419", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0419" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2011-0419", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-0419" } ], "release_date": "2011-05-10T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" }, { "category": "workaround", "details": "mod_autoindex can be configured to ignore request query arguments provided by the client by adding IgnoreClient option to the IndexOptions directive:\n\nhttp://httpd.apache.org/docs/2.2/mod/mod_autoindex.html#indexoptions.ignoreclient", "product_ids": [ "Red Hat JBoss Web Server 1.0" ] } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "apr: unconstrained recursion in apr_fnmatch" }, { "cve": "CVE-2012-4557", "discovery_date": "2012-10-11T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "871685" } ], "notes": [ { "category": "description", "text": "The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.", "title": "Vulnerability description" }, { "category": "summary", "text": "httpd: mod_proxy_ajp worker moved to error state when timeout exceeded", "title": "Vulnerability summary" }, { "category": "other", "text": "This issue did not affect the version of httpd as shipped with Red Hat Enterprise Linux 5.", "title": "Statement" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "Red Hat JBoss Web Server 1.0" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2012-4557" }, { "category": "external", "summary": "RHBZ#871685", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=871685" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2012-4557", "url": "https://www.cve.org/CVERecord?id=CVE-2012-4557" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2012-4557", "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-4557" } ], "release_date": "2012-01-04T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2011-06-22T23:14:00+00:00", "details": "All users of JBoss Enterprise Web Server 1.0.1 as provided from the Red Hat\nCustomer Portal are advised to upgrade to JBoss Enterprise Web Server\n1.0.2, which corrects these issues.\n\nThe References section of this erratum contains a download link (you must\nlog in to download the update). Before installing the update, backup your\nexisting JBoss Enterprise Web Server installation (including all\napplications and configuration files). Apache Tomcat and the Apache HTTP\nServer must be restarted for the update to take effect.", "product_ids": [ "Red Hat JBoss Web Server 1.0" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2011:0896" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P", "version": "2.0" }, "products": [ "Red Hat JBoss Web Server 1.0" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "httpd: mod_proxy_ajp worker moved to error state when timeout exceeded" } ] }
rhsa-2010:0198
Vulnerability from csaf_redhat
Published
2010-03-29 12:00
Modified
2024-11-22 03:29
Summary
Red Hat Security Advisory: openldap security and bug fix update
Notes
Topic
Updated openldap packages that fix one security issue and several bugs are
now available for Red Hat Enterprise Linux 5.
The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.
Details
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools.
A flaw was found in the way OpenLDAP handled NUL characters in the
CommonName field of X.509 certificates. An attacker able to get a
carefully-crafted certificate signed by a trusted Certificate Authority
could trick applications using OpenLDAP libraries into accepting it by
mistake, allowing the attacker to perform a man-in-the-middle attack.
(CVE-2009-3767)
This update also fixes the following bugs:
* the ldap init script did not provide a way to alter system limits for the
slapd daemon. A variable is now available in "/etc/sysconfig/ldap" for this
option. (BZ#527313)
* applications that use the OpenLDAP libraries to contact a Microsoft
Active Directory server could crash when a large number of network
interfaces existed. This update implements locks in the OpenLDAP library
code to resolve this issue. (BZ#510522)
* when slapd was configured to allow client certificates, approximately 90%
of connections froze because of a large CA certificate file and slapd not
checking the success of the SSL handshake. (BZ#509230)
* the OpenLDAP server would freeze for unknown reasons under high load.
These packages add support for accepting incoming connections by new
threads, resolving the issue. (BZ#507276)
* the compat-openldap libraries did not list dependencies on other
libraries, causing programs that did not specifically specify the libraries
to fail. Detection of the Application Binary Interface (ABI) in use on
64-bit systems has been added with this update. (BZ#503734)
* the OpenLDAP libraries caused applications to crash due to an unprocessed
network timeout. A timeval of -1 is now passed when NULL is passed to LDAP.
(BZ#495701)
* slapd could crash on a server under heavy load when using rwm overlay,
caused by freeing non-allocated memory during operation cleanup.
(BZ#495628)
* the ldap init script made a temporary script in "/tmp/" and attempted to
execute it. Problems arose when "/tmp/" was mounted with the noexec option.
The temporary script is no longer created. (BZ#483356)
* the ldap init script always started slapd listening on ldap:/// even if
instructed to listen only on ldaps:///. By correcting the init script, a
user can now select which ports slapd should listen on. (BZ#481003)
* the slapd manual page did not mention the supported options -V and -o.
(BZ#468206)
* slapd.conf had a commented-out option to load the syncprov.la module.
Once un-commented, slapd crashed at start-up because the module had already
been statically linked to OpenLDAP. This update removes "moduleload
syncprov.la" from slapd.conf, which resolves this issue. (BZ#466937)
* the migrate_automount.pl script produced output that was unsupported by
autofs. This is corrected by updating the output LDIF format for automount
records. (BZ#460331)
* the ldap init script uses the TERM signal followed by the KILL signal
when shutting down slapd. Minimal delay between the two signals could cause
the LDAP database to become corrupted if it had not finished saving its
state. A delay between the signals has been added via the "STOP_DELAY"
option in "/etc/sysconfig/ldap". (BZ#452064)
* the migrate_passwd.pl migration script had a problem when number fields
contained only a zero. Such fields were considered to be empty, leading to
the attribute not being set in the LDIF output. The condition in
dump_shadow_attributes has been corrected to allow for the attributes to
contain only a zero. (BZ#113857)
* the migrate_base.pl migration script did not handle third level domains
correctly, creating a second level domain that could not be held by a
database with a three level base. This is now allowed by modifying the
migrate_base.pl script to generate only one domain. (BZ#104585)
Users of OpenLDAP should upgrade to these updated packages, which resolve
these issues.
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Updated openldap packages that fix one security issue and several bugs are\nnow available for Red Hat Enterprise Linux 5.\n\nThe Red Hat Security Response Team has rated this update as having moderate\nsecurity impact. A Common Vulnerability Scoring System (CVSS) base score,\nwhich gives a detailed severity rating, is available from the CVE link in\nthe References section.", "title": "Topic" }, { "category": "general", "text": "OpenLDAP is an open source suite of LDAP (Lightweight Directory Access\nProtocol) applications and development tools.\n\nA flaw was found in the way OpenLDAP handled NUL characters in the\nCommonName field of X.509 certificates. An attacker able to get a\ncarefully-crafted certificate signed by a trusted Certificate Authority\ncould trick applications using OpenLDAP libraries into accepting it by\nmistake, allowing the attacker to perform a man-in-the-middle attack.\n(CVE-2009-3767)\n\nThis update also fixes the following bugs:\n\n* the ldap init script did not provide a way to alter system limits for the\nslapd daemon. A variable is now available in \"/etc/sysconfig/ldap\" for this\noption. (BZ#527313)\n\n* applications that use the OpenLDAP libraries to contact a Microsoft\nActive Directory server could crash when a large number of network\ninterfaces existed. This update implements locks in the OpenLDAP library\ncode to resolve this issue. (BZ#510522)\n\n* when slapd was configured to allow client certificates, approximately 90%\nof connections froze because of a large CA certificate file and slapd not\nchecking the success of the SSL handshake. (BZ#509230)\n\n* the OpenLDAP server would freeze for unknown reasons under high load.\nThese packages add support for accepting incoming connections by new\nthreads, resolving the issue. (BZ#507276)\n\n* the compat-openldap libraries did not list dependencies on other\nlibraries, causing programs that did not specifically specify the libraries\nto fail. Detection of the Application Binary Interface (ABI) in use on\n64-bit systems has been added with this update. (BZ#503734)\n\n* the OpenLDAP libraries caused applications to crash due to an unprocessed\nnetwork timeout. A timeval of -1 is now passed when NULL is passed to LDAP.\n(BZ#495701)\n\n* slapd could crash on a server under heavy load when using rwm overlay,\ncaused by freeing non-allocated memory during operation cleanup.\n(BZ#495628)\n\n* the ldap init script made a temporary script in \"/tmp/\" and attempted to\nexecute it. Problems arose when \"/tmp/\" was mounted with the noexec option.\nThe temporary script is no longer created. (BZ#483356)\n\n* the ldap init script always started slapd listening on ldap:/// even if\ninstructed to listen only on ldaps:///. By correcting the init script, a\nuser can now select which ports slapd should listen on. (BZ#481003)\n\n* the slapd manual page did not mention the supported options -V and -o.\n(BZ#468206)\n\n* slapd.conf had a commented-out option to load the syncprov.la module.\nOnce un-commented, slapd crashed at start-up because the module had already\nbeen statically linked to OpenLDAP. This update removes \"moduleload\nsyncprov.la\" from slapd.conf, which resolves this issue. (BZ#466937)\n\n* the migrate_automount.pl script produced output that was unsupported by\nautofs. This is corrected by updating the output LDIF format for automount\nrecords. (BZ#460331)\n\n* the ldap init script uses the TERM signal followed by the KILL signal\nwhen shutting down slapd. Minimal delay between the two signals could cause\nthe LDAP database to become corrupted if it had not finished saving its\nstate. A delay between the signals has been added via the \"STOP_DELAY\"\noption in \"/etc/sysconfig/ldap\". (BZ#452064)\n\n* the migrate_passwd.pl migration script had a problem when number fields\ncontained only a zero. Such fields were considered to be empty, leading to\nthe attribute not being set in the LDIF output. The condition in\ndump_shadow_attributes has been corrected to allow for the attributes to\ncontain only a zero. (BZ#113857)\n\n* the migrate_base.pl migration script did not handle third level domains\ncorrectly, creating a second level domain that could not be held by a\ndatabase with a three level base. This is now allowed by modifying the\nmigrate_base.pl script to generate only one domain. (BZ#104585)\n\nUsers of OpenLDAP should upgrade to these updated packages, which resolve\nthese issues.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2010:0198", "url": "https://access.redhat.com/errata/RHSA-2010:0198" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "104585", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=104585" }, { "category": "external", "summary": "113857", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=113857" }, { "category": "external", "summary": "460331", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=460331" }, { "category": "external", "summary": "466937", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=466937" }, { "category": "external", "summary": "468206", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=468206" }, { "category": "external", "summary": "481003", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=481003" }, { "category": "external", "summary": "483356", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=483356" }, { "category": "external", "summary": "495701", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=495701" }, { "category": "external", "summary": "503734", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=503734" }, { "category": "external", "summary": "509230", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=509230" }, { "category": "external", "summary": "510522", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=510522" }, { "category": "external", "summary": "530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "559520", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=559520" }, { "category": "external", "summary": "562714", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=562714" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2010/rhsa-2010_0198.json" } ], "title": "Red Hat Security Advisory: openldap security and bug fix update", "tracking": { "current_release_date": "2024-11-22T03:29:50+00:00", "generator": { "date": "2024-11-22T03:29:50+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.2.1" } }, "id": "RHSA-2010:0198", "initial_release_date": "2010-03-29T12:00:00+00:00", "revision_history": [ { "date": "2010-03-29T12:00:00+00:00", "number": "1", "summary": "Initial version" }, { "date": "2010-03-29T09:22:42+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-11-22T03:29:50+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux Desktop (v. 5 client)", "product": { "name": "Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:5::client" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product": { "name": "Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:5::client_workstation" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux (v. 5 server)", "product": { "name": "Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server", "product_identification_helper": { "cpe": "cpe:/o:redhat:enterprise_linux:5::server" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux" }, { "branches": [ { "category": "product_version", "name": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "product_id": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "product_id": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-overlays@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-devel-0:2.3.43-12.el5.x86_64", "product_id": "openldap-devel-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-servers-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-servers-0:2.3.43-12.el5.x86_64", "product_id": "openldap-servers-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-clients-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-clients-0:2.3.43-12.el5.x86_64", "product_id": "openldap-clients-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.3.43-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=x86_64" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.x86_64", "product": { "name": "openldap-0:2.3.43-12.el5.x86_64", "product_id": "openldap-0:2.3.43-12.el5.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=x86_64" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.i386", "product": { "name": "openldap-devel-0:2.3.43-12.el5.i386", "product_id": "openldap-devel-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.i386", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.i386", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-servers-sql-0:2.3.43-12.el5.i386", "product": { "name": "openldap-servers-sql-0:2.3.43-12.el5.i386", "product_id": "openldap-servers-sql-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "product": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "product_id": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-overlays@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-servers-0:2.3.43-12.el5.i386", "product": { "name": "openldap-servers-0:2.3.43-12.el5.i386", "product_id": "openldap-servers-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.i386", "product": { "name": "openldap-0:2.3.43-12.el5.i386", "product_id": "openldap-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=i386" } } }, { "category": "product_version", "name": "openldap-clients-0:2.3.43-12.el5.i386", "product": { "name": "openldap-clients-0:2.3.43-12.el5.i386", "product_id": "openldap-clients-0:2.3.43-12.el5.i386", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.3.43-12.el5?arch=i386" } } } ], "category": "architecture", "name": "i386" }, { "branches": [ { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.src", "product": { "name": "openldap-0:2.3.43-12.el5.src", "product_id": "openldap-0:2.3.43-12.el5.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=src" } } } ], "category": "architecture", "name": "src" }, { "branches": [ { "category": "product_version", "name": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "product_id": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "product_id": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-overlays@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-devel-0:2.3.43-12.el5.ia64", "product_id": "openldap-devel-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-clients-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-clients-0:2.3.43-12.el5.ia64", "product_id": "openldap-clients-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-0:2.3.43-12.el5.ia64", "product_id": "openldap-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=ia64" } } }, { "category": "product_version", "name": "openldap-servers-0:2.3.43-12.el5.ia64", "product": { "name": "openldap-servers-0:2.3.43-12.el5.ia64", "product_id": "openldap-servers-0:2.3.43-12.el5.ia64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.3.43-12.el5?arch=ia64" } } } ], "category": "architecture", "name": "ia64" }, { "branches": [ { "category": "product_version", "name": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "product_id": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "product_id": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-overlays@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-devel-0:2.3.43-12.el5.ppc", "product_id": "openldap-devel-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-clients-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-clients-0:2.3.43-12.el5.ppc", "product_id": "openldap-clients-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-0:2.3.43-12.el5.ppc", "product_id": "openldap-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=ppc" } } }, { "category": "product_version", "name": "openldap-servers-0:2.3.43-12.el5.ppc", "product": { "name": "openldap-servers-0:2.3.43-12.el5.ppc", "product_id": "openldap-servers-0:2.3.43-12.el5.ppc", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.3.43-12.el5?arch=ppc" } } } ], "category": "architecture", "name": "ppc" }, { "branches": [ { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.ppc64", "product": { "name": "openldap-devel-0:2.3.43-12.el5.ppc64", "product_id": "openldap-devel-0:2.3.43-12.el5.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=ppc64" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=ppc64" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=ppc64" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.ppc64", "product": { "name": "openldap-0:2.3.43-12.el5.ppc64", "product_id": "openldap-0:2.3.43-12.el5.ppc64", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=ppc64" } } } ], "category": "architecture", "name": "ppc64" }, { "branches": [ { "category": "product_version", "name": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "product_id": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-sql@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "product_id": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers-overlays@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-devel-0:2.3.43-12.el5.s390x", "product_id": "openldap-devel-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-clients-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-clients-0:2.3.43-12.el5.s390x", "product_id": "openldap-clients-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-clients@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-0:2.3.43-12.el5.s390x", "product_id": "openldap-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=s390x" } } }, { "category": "product_version", "name": "openldap-servers-0:2.3.43-12.el5.s390x", "product": { "name": "openldap-servers-0:2.3.43-12.el5.s390x", "product_id": "openldap-servers-0:2.3.43-12.el5.s390x", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-servers@2.3.43-12.el5?arch=s390x" } } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "openldap-devel-0:2.3.43-12.el5.s390", "product": { "name": "openldap-devel-0:2.3.43-12.el5.s390", "product_id": "openldap-devel-0:2.3.43-12.el5.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-devel@2.3.43-12.el5?arch=s390" } } }, { "category": "product_version", "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "product": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "product_id": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/compat-openldap@2.3.43_2.2.29-12.el5?arch=s390" } } }, { "category": "product_version", "name": "openldap-debuginfo-0:2.3.43-12.el5.s390", "product": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390", "product_id": "openldap-debuginfo-0:2.3.43-12.el5.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap-debuginfo@2.3.43-12.el5?arch=s390" } } }, { "category": "product_version", "name": "openldap-0:2.3.43-12.el5.s390", "product": { "name": "openldap-0:2.3.43-12.el5.s390", "product_id": "openldap-0:2.3.43-12.el5.s390", "product_identification_helper": { "purl": "pkg:rpm/redhat/openldap@2.3.43-12.el5?arch=s390" } } } ], "category": "architecture", "name": "s390" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.i386" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.src as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.src" }, "product_reference": "openldap-0:2.3.43-12.el5.src", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)", "product_id": "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client-Workstation" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.i386" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.src as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.src" }, "product_reference": "openldap-0:2.3.43-12.el5.src", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-clients-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-clients-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-clients-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-clients-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-clients-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-debuginfo-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-devel-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-overlays-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-overlays-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-overlays-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-sql-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-sql-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-sql-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-sql-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)", "product_id": "5Client:openldap-servers-sql-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Client" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.i386" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64" }, "product_reference": "compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.src as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.src" }, "product_reference": "openldap-0:2.3.43-12.el5.src", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-clients-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-clients-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-clients-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-clients-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-clients-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-clients-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-clients-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-debuginfo-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-debuginfo-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-debuginfo-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.ppc64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.ppc64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.s390" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-devel-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-devel-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-devel-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-overlays-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-overlays-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-overlays-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.i386 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-sql-0:2.3.43-12.el5.i386" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.i386", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-sql-0:2.3.43-12.el5.ia64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ia64", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.ppc as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-sql-0:2.3.43-12.el5.ppc" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.ppc", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.s390x as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-sql-0:2.3.43-12.el5.s390x" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.s390x", "relates_to_product_reference": "5Server" }, { "category": "default_component_of", "full_product_name": { "name": "openldap-servers-sql-0:2.3.43-12.el5.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)", "product_id": "5Server:openldap-servers-sql-0:2.3.43-12.el5.x86_64" }, "product_reference": "openldap-servers-sql-0:2.3.43-12.el5.x86_64", "relates_to_product_reference": "5Server" } ] }, "vulnerabilities": [ { "cve": "CVE-2009-3767", "discovery_date": "2009-08-21T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "530715" } ], "notes": [ { "category": "description", "text": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "title": "Vulnerability description" }, { "category": "summary", "text": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name", "title": "Vulnerability summary" }, { "category": "other", "text": "This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.\n\nThe Red Hat Security Response Team has rated this issue as having moderate security impact, a future openldap update may address this flaw in Red Hat Enterprise Linux 3.", "title": "Statement" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client-Workstation:openldap-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-0:2.3.43-12.el5.src", "5Client-Workstation:openldap-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client:openldap-0:2.3.43-12.el5.i386", "5Client:openldap-0:2.3.43-12.el5.ia64", "5Client:openldap-0:2.3.43-12.el5.ppc", "5Client:openldap-0:2.3.43-12.el5.ppc64", "5Client:openldap-0:2.3.43-12.el5.s390", "5Client:openldap-0:2.3.43-12.el5.s390x", "5Client:openldap-0:2.3.43-12.el5.src", "5Client:openldap-0:2.3.43-12.el5.x86_64", "5Client:openldap-clients-0:2.3.43-12.el5.i386", "5Client:openldap-clients-0:2.3.43-12.el5.ia64", "5Client:openldap-clients-0:2.3.43-12.el5.ppc", "5Client:openldap-clients-0:2.3.43-12.el5.s390x", "5Client:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client:openldap-devel-0:2.3.43-12.el5.i386", "5Client:openldap-devel-0:2.3.43-12.el5.ia64", "5Client:openldap-devel-0:2.3.43-12.el5.ppc", "5Client:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client:openldap-devel-0:2.3.43-12.el5.s390", "5Client:openldap-devel-0:2.3.43-12.el5.s390x", "5Client:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-0:2.3.43-12.el5.i386", "5Client:openldap-servers-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Server:openldap-0:2.3.43-12.el5.i386", "5Server:openldap-0:2.3.43-12.el5.ia64", "5Server:openldap-0:2.3.43-12.el5.ppc", "5Server:openldap-0:2.3.43-12.el5.ppc64", "5Server:openldap-0:2.3.43-12.el5.s390", "5Server:openldap-0:2.3.43-12.el5.s390x", "5Server:openldap-0:2.3.43-12.el5.src", "5Server:openldap-0:2.3.43-12.el5.x86_64", "5Server:openldap-clients-0:2.3.43-12.el5.i386", "5Server:openldap-clients-0:2.3.43-12.el5.ia64", "5Server:openldap-clients-0:2.3.43-12.el5.ppc", "5Server:openldap-clients-0:2.3.43-12.el5.s390x", "5Server:openldap-clients-0:2.3.43-12.el5.x86_64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Server:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Server:openldap-devel-0:2.3.43-12.el5.i386", "5Server:openldap-devel-0:2.3.43-12.el5.ia64", "5Server:openldap-devel-0:2.3.43-12.el5.ppc", "5Server:openldap-devel-0:2.3.43-12.el5.ppc64", "5Server:openldap-devel-0:2.3.43-12.el5.s390", "5Server:openldap-devel-0:2.3.43-12.el5.s390x", "5Server:openldap-devel-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-0:2.3.43-12.el5.i386", "5Server:openldap-servers-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-sql-0:2.3.43-12.el5.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2009-3767" }, { "category": "external", "summary": "RHBZ#530715", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=530715" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2009-3767", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3767" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767" } ], "release_date": "2009-08-10T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2010-03-29T12:00:00+00:00", "details": "Before applying this update, make sure all previously-released errata\nrelevant to your system have been applied.\n\nThis update is available via the Red Hat Network. Details on how to\nuse the Red Hat Network to apply this update are available at\nhttp://kbase.redhat.com/faq/docs/DOC-11259", "product_ids": [ "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client-Workstation:openldap-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-0:2.3.43-12.el5.src", "5Client-Workstation:openldap-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client:openldap-0:2.3.43-12.el5.i386", "5Client:openldap-0:2.3.43-12.el5.ia64", "5Client:openldap-0:2.3.43-12.el5.ppc", "5Client:openldap-0:2.3.43-12.el5.ppc64", "5Client:openldap-0:2.3.43-12.el5.s390", "5Client:openldap-0:2.3.43-12.el5.s390x", "5Client:openldap-0:2.3.43-12.el5.src", "5Client:openldap-0:2.3.43-12.el5.x86_64", "5Client:openldap-clients-0:2.3.43-12.el5.i386", "5Client:openldap-clients-0:2.3.43-12.el5.ia64", "5Client:openldap-clients-0:2.3.43-12.el5.ppc", "5Client:openldap-clients-0:2.3.43-12.el5.s390x", "5Client:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client:openldap-devel-0:2.3.43-12.el5.i386", "5Client:openldap-devel-0:2.3.43-12.el5.ia64", "5Client:openldap-devel-0:2.3.43-12.el5.ppc", "5Client:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client:openldap-devel-0:2.3.43-12.el5.s390", "5Client:openldap-devel-0:2.3.43-12.el5.s390x", "5Client:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-0:2.3.43-12.el5.i386", "5Client:openldap-servers-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Server:openldap-0:2.3.43-12.el5.i386", "5Server:openldap-0:2.3.43-12.el5.ia64", "5Server:openldap-0:2.3.43-12.el5.ppc", "5Server:openldap-0:2.3.43-12.el5.ppc64", "5Server:openldap-0:2.3.43-12.el5.s390", "5Server:openldap-0:2.3.43-12.el5.s390x", "5Server:openldap-0:2.3.43-12.el5.src", "5Server:openldap-0:2.3.43-12.el5.x86_64", "5Server:openldap-clients-0:2.3.43-12.el5.i386", "5Server:openldap-clients-0:2.3.43-12.el5.ia64", "5Server:openldap-clients-0:2.3.43-12.el5.ppc", "5Server:openldap-clients-0:2.3.43-12.el5.s390x", "5Server:openldap-clients-0:2.3.43-12.el5.x86_64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Server:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Server:openldap-devel-0:2.3.43-12.el5.i386", "5Server:openldap-devel-0:2.3.43-12.el5.ia64", "5Server:openldap-devel-0:2.3.43-12.el5.ppc", "5Server:openldap-devel-0:2.3.43-12.el5.ppc64", "5Server:openldap-devel-0:2.3.43-12.el5.s390", "5Server:openldap-devel-0:2.3.43-12.el5.s390x", "5Server:openldap-devel-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-0:2.3.43-12.el5.i386", "5Server:openldap-servers-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-sql-0:2.3.43-12.el5.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2010:0198" } ], "scores": [ { "cvss_v2": { "accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.6, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client-Workstation:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client-Workstation:openldap-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-0:2.3.43-12.el5.src", "5Client-Workstation:openldap-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client-Workstation:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Client:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Client:openldap-0:2.3.43-12.el5.i386", "5Client:openldap-0:2.3.43-12.el5.ia64", "5Client:openldap-0:2.3.43-12.el5.ppc", "5Client:openldap-0:2.3.43-12.el5.ppc64", "5Client:openldap-0:2.3.43-12.el5.s390", "5Client:openldap-0:2.3.43-12.el5.s390x", "5Client:openldap-0:2.3.43-12.el5.src", "5Client:openldap-0:2.3.43-12.el5.x86_64", "5Client:openldap-clients-0:2.3.43-12.el5.i386", "5Client:openldap-clients-0:2.3.43-12.el5.ia64", "5Client:openldap-clients-0:2.3.43-12.el5.ppc", "5Client:openldap-clients-0:2.3.43-12.el5.s390x", "5Client:openldap-clients-0:2.3.43-12.el5.x86_64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Client:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Client:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Client:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Client:openldap-devel-0:2.3.43-12.el5.i386", "5Client:openldap-devel-0:2.3.43-12.el5.ia64", "5Client:openldap-devel-0:2.3.43-12.el5.ppc", "5Client:openldap-devel-0:2.3.43-12.el5.ppc64", "5Client:openldap-devel-0:2.3.43-12.el5.s390", "5Client:openldap-devel-0:2.3.43-12.el5.s390x", "5Client:openldap-devel-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-0:2.3.43-12.el5.i386", "5Client:openldap-servers-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Client:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Client:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Client:openldap-servers-sql-0:2.3.43-12.el5.x86_64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.i386", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ia64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.ppc64", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.s390x", "5Server:compat-openldap-0:2.3.43_2.2.29-12.el5.x86_64", "5Server:openldap-0:2.3.43-12.el5.i386", "5Server:openldap-0:2.3.43-12.el5.ia64", "5Server:openldap-0:2.3.43-12.el5.ppc", "5Server:openldap-0:2.3.43-12.el5.ppc64", "5Server:openldap-0:2.3.43-12.el5.s390", "5Server:openldap-0:2.3.43-12.el5.s390x", "5Server:openldap-0:2.3.43-12.el5.src", "5Server:openldap-0:2.3.43-12.el5.x86_64", "5Server:openldap-clients-0:2.3.43-12.el5.i386", "5Server:openldap-clients-0:2.3.43-12.el5.ia64", "5Server:openldap-clients-0:2.3.43-12.el5.ppc", "5Server:openldap-clients-0:2.3.43-12.el5.s390x", "5Server:openldap-clients-0:2.3.43-12.el5.x86_64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.i386", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ia64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc", "5Server:openldap-debuginfo-0:2.3.43-12.el5.ppc64", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390", "5Server:openldap-debuginfo-0:2.3.43-12.el5.s390x", "5Server:openldap-debuginfo-0:2.3.43-12.el5.x86_64", "5Server:openldap-devel-0:2.3.43-12.el5.i386", "5Server:openldap-devel-0:2.3.43-12.el5.ia64", "5Server:openldap-devel-0:2.3.43-12.el5.ppc", "5Server:openldap-devel-0:2.3.43-12.el5.ppc64", "5Server:openldap-devel-0:2.3.43-12.el5.s390", "5Server:openldap-devel-0:2.3.43-12.el5.s390x", "5Server:openldap-devel-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-0:2.3.43-12.el5.i386", "5Server:openldap-servers-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.i386", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-overlays-0:2.3.43-12.el5.x86_64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.i386", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ia64", "5Server:openldap-servers-sql-0:2.3.43-12.el5.ppc", "5Server:openldap-servers-sql-0:2.3.43-12.el5.s390x", "5Server:openldap-servers-sql-0:2.3.43-12.el5.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "OpenLDAP: Doesn\u0027t properly handle NULL character in subject Common Name" } ] }
ghsa-hc4m-gmh3-4vxp
Vulnerability from github
Published
2022-05-02 03:48
Modified
2022-05-02 03:48
VLAI Severity ?
Details
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
{ "affected": [], "aliases": [ "CVE-2009-3767" ], "database_specific": { "cwe_ids": [ "CWE-295" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2009-10-23T19:30:00Z", "severity": "MODERATE" }, "details": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "id": "GHSA-hc4m-gmh3-4vxp", "modified": "2022-05-02T03:48:23Z", "published": "2022-05-02T03:48:23Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3767" }, { "type": "WEB", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "type": "WEB", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "type": "WEB", "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "type": "WEB", "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" }, { "type": "WEB", "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "type": "WEB", "url": "http://secunia.com/advisories/38769" }, { "type": "WEB", "url": "http://secunia.com/advisories/40677" }, { "type": "WEB", "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "type": "WEB", "url": "http://support.apple.com/kb/HT3937" }, { "type": "WEB", "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "type": "WEB", "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "type": "WEB", "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2010/1858" } ], "schema_version": "1.4.0", "severity": [] }
fkie_cve-2009-3767
Vulnerability from fkie_nvd
Published
2009-10-23 19:30
Modified
2025-04-09 00:30
Severity ?
Summary
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
References
▶ | URL | Tags | |
---|---|---|---|
cve@mitre.org | http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html | Mailing List, Third Party Advisory | |
cve@mitre.org | http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html | Third Party Advisory | |
cve@mitre.org | http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html | Mailing List, Third Party Advisory | |
cve@mitre.org | http://marc.info/?l=oss-security&m=125198917018936&w=2 | Third Party Advisory | |
cve@mitre.org | http://marc.info/?l=oss-security&m=125369675820512&w=2 | Third Party Advisory | |
cve@mitre.org | http://secunia.com/advisories/38769 | Third Party Advisory | |
cve@mitre.org | http://secunia.com/advisories/40677 | Third Party Advisory | |
cve@mitre.org | http://security.gentoo.org/glsa/glsa-201406-36.xml | Third Party Advisory | |
cve@mitre.org | http://support.apple.com/kb/HT3937 | Broken Link | |
cve@mitre.org | http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8&r2=1.11&f=h | Patch, Vendor Advisory | |
cve@mitre.org | http://www.redhat.com/support/errata/RHSA-2010-0543.html | Third Party Advisory | |
cve@mitre.org | http://www.redhat.com/support/errata/RHSA-2011-0896.html | Third Party Advisory | |
cve@mitre.org | http://www.vupen.com/english/advisories/2009/3056 | Third Party Advisory | |
cve@mitre.org | http://www.vupen.com/english/advisories/2010/1858 | Third Party Advisory | |
cve@mitre.org | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178 | Third Party Advisory | |
cve@mitre.org | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://marc.info/?l=oss-security&m=125198917018936&w=2 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://marc.info/?l=oss-security&m=125369675820512&w=2 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://secunia.com/advisories/38769 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://secunia.com/advisories/40677 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://security.gentoo.org/glsa/glsa-201406-36.xml | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://support.apple.com/kb/HT3937 | Broken Link | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8&r2=1.11&f=h | Patch, Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.redhat.com/support/errata/RHSA-2010-0543.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.redhat.com/support/errata/RHSA-2011-0896.html | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.vupen.com/english/advisories/2009/3056 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.vupen.com/english/advisories/2010/1858 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274 | Third Party Advisory |
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*", "matchCriteriaId": "1479E6E9-32C0-437A-97D0-896D354BCF46", "versionEndExcluding": "2.4.18", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*", "matchCriteriaId": "DDA1CA86-1405-4C25-9BC2-5A5E6A76B911", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "matchCriteriaId": "8333C974-DF5B-4098-A766-EB8D875817F5", "versionEndExcluding": "10.6.2", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*", "matchCriteriaId": "B3BB5EDB-520B-4DEF-B06E-65CA13152824", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408." }, { "lang": "es", "value": "libraries/libldap/tls_o.c en OpenLDAP, cuando se usa OpenSSL, no maneja de forma adecuada el caracter \u0027\\0\u0027 en un nombre de dominio, dentro del campo sujeto del Common Name (CN) en los certificados X.509, lo\r\nque permite a atacantes man-in-the-middle, esp\u00edar servidores SSL de su elecci\u00f3n a trav\u00e9s de certificados manipulados concedidos por Autoridades Certificadoras, esta relacionado con CVE-2009-2408.\r\n" } ], "id": "CVE-2009-3767", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2009-10-23T19:30:00.250", "references": [ { "source": "cve@mitre.org", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "source": "cve@mitre.org", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/38769" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/40677" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "source": "cve@mitre.org", "tags": [ "Broken Link" ], "url": "http://support.apple.com/kb/HT3937" }, { "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/38769" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/40677" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link" ], "url": "http://support.apple.com/kb/HT3937" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" } ], "sourceIdentifier": "cve@mitre.org", "vendorComments": [ { "comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3767\n\nThis issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.\n\nThe Red Hat Security Response Team has rated this issue as having moderate security impact, a future openldap update may address this flaw in Red Hat Enterprise Linux 3.", "lastModified": "2010-07-20T00:00:00", "organization": "Red Hat" }, { "comment": "OpenLDAP reported this issue and published a patch for it on 2009-07-30. The patch was included in OpenLDAP 2.4.18 which was released on 2009-09-06. The current release of OpenLDAP is available from the following location:\n\nhttp://www.openldap.org/software/download/", "lastModified": "2009-10-30T00:00:00", "organization": "OpenLDAP" } ], "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-295" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
gsd-2009-3767
Vulnerability from gsd
Modified
2023-12-13 01:19
Details
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2009-3767", "description": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "id": "GSD-2009-3767", "references": [ "https://www.suse.com/security/cve/CVE-2009-3767.html", "https://www.debian.org/security/2009/dsa-1943", "https://access.redhat.com/errata/RHSA-2011:0896", "https://access.redhat.com/errata/RHSA-2010:0543", "https://access.redhat.com/errata/RHSA-2010:0198", "https://linux.oracle.com/cve/CVE-2009-3767.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2009-3767" ], "details": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", "id": "GSD-2009-3767", "modified": "2023-12-13T01:19:48.857118Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-3767", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "FEDORA-2010-0752", "refsource": "FEDORA", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "name": "[oss-security] 20090923 Re: More CVE-2009-2408 like issues", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "name": "GLSA-201406-36", "refsource": "GENTOO", "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "name": "oval:org.mitre.oval:def:11178", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" }, { "name": "ADV-2010-1858", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "name": "40677", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/40677" }, { "name": "oval:org.mitre.oval:def:7274", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "name": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h", "refsource": "CONFIRM", "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "name": "ADV-2009-3056", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "name": "RHSA-2010:0543", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "name": "RHSA-2011:0896", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "name": "SUSE-SR:2009:016", "refsource": "SUSE", "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "name": "38769", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/38769" }, { "name": "APPLE-SA-2009-11-09-1", "refsource": "APPLE", "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "name": "http://support.apple.com/kb/HT3937", "refsource": "CONFIRM", "url": "http://support.apple.com/kb/HT3937" }, { "name": "[oss-security] 20090903 More CVE-2009-2408 like issues", "refsource": "MLIST", "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "2.4.18", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": false } ], "operator": "OR" } ], "cpe_match": [], "operator": "AND" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "10.6.2", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-3767" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a \u0027\\0\u0027 character in a domain name in the subject\u0027s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-295" } ] } ] }, "references": { "reference_data": [ { "name": "SUSE-SR:2009:016", "refsource": "SUSE", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" }, { "name": "[oss-security] 20090903 More CVE-2009-2408 like issues", "refsource": "MLIST", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125198917018936\u0026w=2" }, { "name": "[oss-security] 20090923 Re: More CVE-2009-2408 like issues", "refsource": "MLIST", "tags": [ "Third Party Advisory" ], "url": "http://marc.info/?l=oss-security\u0026m=125369675820512\u0026w=2" }, { "name": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h", "refsource": "CONFIRM", "tags": [ "Patch", "Vendor Advisory" ], "url": "http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8\u0026r2=1.11\u0026f=h" }, { "name": "ADV-2009-3056", "refsource": "VUPEN", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2009/3056" }, { "name": "APPLE-SA-2009-11-09-1", "refsource": "APPLE", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" }, { "name": "http://support.apple.com/kb/HT3937", "refsource": "CONFIRM", "tags": [ "Broken Link" ], "url": "http://support.apple.com/kb/HT3937" }, { "name": "FEDORA-2010-0752", "refsource": "FEDORA", "tags": [ "Third Party Advisory" ], "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036138.html" }, { "name": "38769", "refsource": "SECUNIA", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/38769" }, { "name": "40677", "refsource": "SECUNIA", "tags": [ "Third Party Advisory" ], "url": "http://secunia.com/advisories/40677" }, { "name": "ADV-2010-1858", "refsource": "VUPEN", "tags": [ "Third Party Advisory" ], "url": "http://www.vupen.com/english/advisories/2010/1858" }, { "name": "RHSA-2010:0543", "refsource": "REDHAT", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2010-0543.html" }, { "name": "RHSA-2011:0896", "refsource": "REDHAT", "tags": [ "Third Party Advisory" ], "url": "http://www.redhat.com/support/errata/RHSA-2011-0896.html" }, { "name": "GLSA-201406-36", "refsource": "GENTOO", "tags": [ "Third Party Advisory" ], "url": "http://security.gentoo.org/glsa/glsa-201406-36.xml" }, { "name": "oval:org.mitre.oval:def:7274", "refsource": "OVAL", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7274" }, { "name": "oval:org.mitre.oval:def:11178", "refsource": "OVAL", "tags": [ "Third Party Advisory" ], "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11178" } ] } }, "impact": { "baseMetricV2": { "acInsufInfo": false, "cvssV2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false } }, "lastModifiedDate": "2020-10-14T17:13Z", "publishedDate": "2009-10-23T19:30Z" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…