OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.
| Software | From | Fixed in |
|---|---|---|
| openldap / openldap | 1.2.7 | 1.2.7.x |
| openldap / openldap | 1.2.11 | 1.2.11.x |
| openldap / openldap | 1.2.10 | 1.2.10.x |
| openldap / openldap | 1.2.8 | 1.2.8.x |
| openldap / openldap | 1.2.9 | 1.2.9.x |