Bugzilla – Bug 882792
VUL-0: CVE-2014-3999: php5-pear-Horde_Ldap: connect to LDAP without knowing the password
Last modified: 2017-08-03 14:04:16 UTC
If a user knows the LDAP bind user's DN, they can login without supplying a password. This has been fixed in version 2.0.6. References: http://seclists.org/oss-sec/2014/q2/504 https://bugzilla.redhat.com/show_bug.cgi?id=1109628 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3999 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3999.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3999
Ralf, there is no bugowner for this package. Can you please fix this bug (and maybe even take the bugowner role)?
Yes I can take over. I recommend using upstream's updated package version and will provide it through the obs workflow.
bugbot adjusting priority
ping
fixed in Factory, not on Leap