Total vulnerabilities in the database
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
Software | From | Fixed in |
---|---|---|
openldap / openldap | - | 2.0.19.x |
openldap / openldap | 2.0 | 2.0.x |
redhat / linux | 7.0 | 7.0.x |
redhat / linux | 7.2 | 7.2.x |
redhat / linux | 7.1 | 7.1.x |