Notified: December 09, 2004 Updated: January 14, 2005
Not Affected
Mac OS X v10.2.x and Mac OS X Server v10.2.x or earlier are not affected by this issue as they do not contain the vulnerable versions of the LDAP server. Mac OS X v10.3.x and Mac OS X Server v10.3.x are not affected by this issue in their supported configurations.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Not Affected
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 16, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Unknown
Related information will be published on http://software.fujitsu.com/jp/security/vuls/vuls.html#1BF8D7AA_ldap
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 11, 2005
Affected
HP has released a Security Bulletin to address this issue. For further information, please refer to the following URL: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBUX01105
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Affected
Hitachi Directory Server Version 2 is vulnerable to this issue. More details are available at http://www.hitachi-support.com/security_e/vuls_e/HS05-001_e/index-e.html
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 11, 2005
Not Affected
Juniper Networks products are not susceptible to this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 16, 2004
Not Affected
The IBM Lotus Domino server is not vulnerable to this LDAP issue.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 05, 2005
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Not Affected
Related information is published on http://www.sw.nec.co.jp/psirt/bnin2005.html#1
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 16, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Updated: January 11, 2005
Affected
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
A statement provided by Red Hat concerning Netscape Directory Server version 6.21 and earlier can be found at the following URL: https://www.kb.cert.org/vulcatalog/id/SSTT-67PTDF
Notified: December 09, 2004 Updated: December 16, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 14, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 11, 2005
Not Affected
The OpenLDAP Project has evaluated OpenLDAP Software 2.2.17 (current "stable" version) and OpenLDAP Software 2.2.19 (current "release" version) as well as development and release engineering sources, as distributed by the OpenLDAP Project. We found that long attribute names in LDAP request PDUs do not cause a buffer overflow, nor even lead to unexpected behavior (regardless of whether the long attribute name is defined or not in the subschema). The OpenLDAP Project did not evaluate older versions of OpenLDAP Software. As these versions are no longer maintained by the OpenLDAP Project, the OpenLDAP Project recommends (irregardless of this issue) that users of these versions consider upgrading to a current version. The OpenLDAP Project also did not evaluate any 3rd party software, including software based upon (in any fashion) OpenLDAP Software.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 14, 2004 Updated: December 17, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 14, 2004 Updated: December 17, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Not Affected
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 10, 2005
Affected
Vendor Statement: Red Hat, Inc: Netscape Directory Server version 6.21 and earlier are vulnerable to this issue. In December 2004 Red Hat aquired the Netscape Directory Server product from America Online, Inc. Patches are available by contacting the Red Hat Security Response Team by email at secalert@redhat.com. More details are available at http://rhn.redhat.com/errata/RHSA-2005-030.html
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: January 11, 2005
Not Affected
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 14, 2004 Updated: December 17, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 10, 2004 Updated: January 13, 2005
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.
Notified: December 09, 2004 Updated: December 15, 2004
Unknown
No statement is currently available from the vendor regarding this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
US-CERT has no additional comments at this time.