
                       The U.S. Department of Energy
                   Computer Incident Advisory Capability
                           ___  __ __    _     ___
                          /       |     /_\   /
                          \___  __|__  /   \  \___

                             INFORMATION BULLETIN

                           auth_ldap Security Update

January 10, 2006 22:00 GMT                                        Number Q-094
[REVISED 23 Jan 2006]
PROBLEM:       A format string flaw was found in the way auth_ldap logs 
PLATFORM:      Red Hat Enterprise Linux AS (v. 2.1) 
               Red Hat Enterprise Linux ES (v. 2.1) 
               Red Hat Enterprise Linux WS (v. 2.1) 
               Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor 
			   Debian GNU/Linux 3.0 alias woody
DAMAGE:        It may be possible for a remote attacker to execute arbitrary 
               code as the 'apache' user if auth_ldap is used for user 
SOLUTION:      Apply current patches. 
VULNERABILITY  The risk is MEDIUM. A remote attacker could execute arbitrary 
ASSESSMENT:    code. 
 CIAC BULLETIN:      http://www.ciac.org/ciac/bulletins/q-094.shtml 
 ORIGINAL BULLETIN:  https://rhn.redhat.com/errata/RHSA-2006-0179.html 
 ADDITIONAL LINK:    http://www.debian.org/security/2006/dsa-952
 CVE:                http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= 
01/23/2006 - revised to add a link to Debian Security Advisory DSA-952-1 for 
             Debian GNU/Linux 3.0 alias woody.
[***** Start RHSA-2006:0179-7 *****]

Critical: auth_ldap security update
Advisory: 	RHSA-2006:0179-7
Type: 	Security Advisory
Issued on: 	2006-01-10
Last updated on: 	2006-01-10
Affected Products: 	Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): 	CVE-2006-0150


An updated auth_ldap packages that fixes a format string security issue is
now available for Red Hat Enterprise Linux 2.1.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The auth_ldap package is an httpd module that allows user authentication
against information stored in an LDAP database.

A format string flaw was found in the way auth_ldap logs information. It
may be possible for a remote attacker to execute arbitrary code as the
'apache' user if auth_ldap is used for user authentication. The Common
Vulnerabilities and Exposures project assigned the name CVE-2006-0150
to this issue.

Note that this issue only affects servers that have auth_ldap installed and
configured to perform user authentication against an LDAP database.

All users of auth_ldap should upgrade to this updated package, which
contains a backported patch to resolve this issue.

This issue does not affect the Red Hat Enterprise Linux 3 or 4
distributions as they do not include the auth_ldap package.

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:


This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages
Red Hat Enterprise Linux AS (v. 2.1)
auth_ldap-1.4.8-3.1.src.rpm 	    b386cc76da4f4dbbcafc5e0200567b76
auth_ldap-1.4.8-3.1.i386.rpm 	    569bce40fcb6cc7cefa9179d949fb192
auth_ldap-1.4.8-3.1.ia64.rpm 	    56aea79641ddb17dc98d26b6f20dd439
Red Hat Enterprise Linux ES (v. 2.1)
auth_ldap-1.4.8-3.1.src.rpm 	    b386cc76da4f4dbbcafc5e0200567b76
auth_ldap-1.4.8-3.1.i386.rpm 	    569bce40fcb6cc7cefa9179d949fb192
Red Hat Enterprise Linux WS (v. 2.1)
auth_ldap-1.4.8-3.1.src.rpm 	    b386cc76da4f4dbbcafc5e0200567b76
auth_ldap-1.4.8-3.1.i386.rpm 	    569bce40fcb6cc7cefa9179d949fb192
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
auth_ldap-1.4.8-3.1.src.rpm 	    b386cc76da4f4dbbcafc5e0200567b76
auth_ldap-1.4.8-3.1.ia64.rpm 	    56aea79641ddb17dc98d26b6f20dd439
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

177421 - CVE-2006-0150 auth_ldap format string issue


[***** End RHSA-2006:0179-7 *****]

CIAC wishes to acknowledge the contributions of RedHat for the 
information contained in this bulletin.

CIAC, the Computer Incident Advisory Capability, is the computer
security incident response team for the U.S. Department of Energy
(DOE) and the emergency backup response team for the National
Institutes of Health (NIH). CIAC is located at the Lawrence Livermore
National Laboratory in Livermore, California. CIAC is also a founding
member of FIRST, the Forum of Incident Response and Security Teams, a
global organization established to foster cooperation and coordination
among computer security teams worldwide.

CIAC services are available to DOE, DOE contractors, and the NIH. CIAC
can be contacted at:
    Voice:    +1 925-422-8193 (7x24)
    FAX:      +1 925-423-8002
    STU-III:  +1 925-423-2604
    E-mail:   ciac@ciac.org

Previous CIAC notices, anti-virus software, and other information are
available from the CIAC Computer Security Archive.

   World Wide Web:      http://www.ciac.org/
   Anonymous FTP:       ftp.ciac.org

PLEASE NOTE: Many users outside of the DOE, ESnet, and NIH computing
communities receive CIAC bulletins.  If you are not part of these
communities, please contact your agency's response team to report
incidents. Your agency's team will coordinate with CIAC. The Forum of
Incident Response and Security Teams (FIRST) is a world-wide
organization. A list of FIRST member organizations and their
constituencies can be obtained via WWW at http://www.first.org/.

This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.

LAST 10 CIAC BULLETINS ISSUED (Previous bulletins available from CIAC)

Q-084: Cisco Security Notice: Response to DoS in Cisco Clean Access
Q-085: Microsoft Windows Metafile File (WMF) Vulnerability
Q-086: MS Advisory Win32/Sober.Z@mm on January 6, 2006
Q-087: Blackberry Attachment Service Vulnerability
Q-088: Perl Format String Vulnerabilities
Q-089: httpd Security Update
Q-090: Vulnerability in Graphics Rendering Engine 
Q-091: mod_auth_pgsql Security Update
Q-092: xpdf Buffer Overflows
Q-093: libapache2-mod-auth-pgsql