OBSOLETE Patch-ID# 111090-03 Keywords: security ldap NS_LDAP_SEARCH_DN password ldapclient replica Synopsis: Obsoleted by: 108993-05 SunOS 5.8: /usr/lib/libsldap.so.1 patch Date: Aug/06/2001 Solaris Release: 8 SunOS Release: 5.8 Unbundled Product: Unbundled Release: Xref: This patch is available for x86 as patch 111091 Topic: SunOS 5.8: /usr/lib/libsldap.so.1 patch Relevant Architectures: sparc BugId's fixed with this patch: 4357912 4359656 4449613 Changes incorporated in this version: 4449613 Patches accumulated and obsoleted by this patch: Patches which conflict with this patch: Patches required with this patch: Obsoleted by: 108993-05 Files included with this patch: /usr/lib/libsldap.so.1 /usr/lib/sparcv9/libsldap.so.1 Problem Description: 4449613 Buffer overflow in libsldap.so.1 leads to root compromise (from 111090-02) 4357912 cannot change password when ldapclient set to use a replica (from 111090-01) 4359656 ldap backend does not search multiple paths as per NS_LDAP_SEARCH_DN parameter Patch Installation Instructions: -------------------------------- For Solaris 2.0-2.6 releases, refer to the Install.info file and/or the README within the patch for instructions on using the generic 'installpatch' and 'backoutpatch' scripts provided with each patch. For Solaris 7-8 releases, refer to the man pages for instructions on using 'patchadd' and 'patchrm' scripts provided with Solaris. Any other special or non-generic installation instructions should be described below as special instructions. The following example installs a patch to a standalone machine: example# patchadd /var/spool/patch/104945-02 The following example removes a patch from a standalone system: example# patchrm 104945-02 For additional examples please see the appropriate man pages. Special Install Instructions: ----------------------------- None. README -- Last modified date: Friday, November 30, 2001