Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
References
Link Providers
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453868 cve-icon cve-icon
http://bugs.gentoo.org/show_bug.cgi?id=198390 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html cve-icon cve-icon
http://secunia.com/advisories/27670 cve-icon cve-icon
http://secunia.com/advisories/27768 cve-icon cve-icon
http://secunia.com/advisories/27839 cve-icon cve-icon
http://secunia.com/advisories/28061 cve-icon cve-icon
http://secunia.com/advisories/28838 cve-icon cve-icon
http://secunia.com/advisories/29083 cve-icon cve-icon
http://secunia.com/advisories/30352 cve-icon cve-icon
http://secunia.com/advisories/31227 cve-icon cve-icon
http://secunia.com/advisories/31524 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200711-33.xml cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-332.htm cve-icon cve-icon
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0255 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1430 cve-icon cve-icon
http://www.dovecot.org/list/dovecot/2005-April/006859.html cve-icon cve-icon
http://www.dovecot.org/list/dovecot/2005-March/006345.html cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:049 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0389.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0715.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/487985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/26452 cve-icon cve-icon
http://www.securitytracker.com/id?1020088 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=154314 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=367461 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/38505 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1913 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-5794 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10625 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-5794 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-11-13T23:00:00

Updated: 2024-08-07T15:46:59.521Z

Reserved: 2007-11-02T00:00:00

Link: CVE-2007-5794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-11-13T23:46:00.000

Modified: 2024-11-21T00:38:42.583

Link: CVE-2007-5794

cve-icon Redhat

Severity : Low

Publid Date: 2005-04-09T00:00:00Z

Links: CVE-2007-5794 - Bugzilla