OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
Link | Tags |
---|---|
http://www.novell.com/linux/security/advisories/2002_047_openldap2.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2003:006 | vendor advisory |
http://www.debian.org/security/2003/dsa-227 | patch vendor advisory |