- Issued:
- 2011-12-06
- Updated:
- 2012-02-13
RHBA-2011:1705 - Bug Fix Advisory
Synopsis
nss-pam-ldapd bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An updated nss-pam-ldapd package that fixes multiple bugs and adds one
enhancement is now available for Red Hat Enterprise Linux 6.
[Updated 24 January 2012] This advisory has been updated with the correct
package description in the Details section. The package included in this revised
update has not been changed in any way from the package included in the original
advisory.
Description
The nss-pam-ldapd package provides the nss-pam-ldapd daemon (nslcd) which uses a
directory server to look up name service information on behalf of a lightweight
nsswitch module.
This update fixes the following bugs:
- When the nss-pam-ldapd package was installed, settings for the nslcd daemon
were migrated from the configuration files used by the pam_ldap module or a
previously-installed copy of the nss_ldap package. If the nslcd configuration
file was modified, settings would be migrated again, often with an error. With
this update, the migration is performed only if the package has not been
previously installed. (BZ#706454)
- Prior to this update, when the nslcd daemon retrieved information about a user
or group, the name of the user or group would be checked against the value of
the "validnames" configuration setting. The default value of the setting
expected the names to be at least three characters long, therefore names which
were only two characters long were flagged as invalid. This could have negative
impact on some installations. With this update, the default value of the
"validnames" setting is modified to a minimum of two characters so that short
names are accepted. (BZ#706860)
- Due to the buffer used for the group field of a user password entry being not
big enough, the primary group ID of a user could not be parsed if it contained
more than nine digits. As a consequence, the nslcd daemon could drop some of the
digits. With this update, nslcd is modified to parse large user IDs properly.
(BZ#716822, BZ#720230)
- An incorrect use of the strtol() call could cause large user ID values to
overflow on 32-bit architectures. New functions have been implemented with this
update, so that large user IDs are parsed correctly. (BZ#741362)
This update also provides the following enhancement:
- Previously, if "DNS" was specified as the value of the LDAP "uri" setting in
the /etc/nslcd.conf file, the nslcd service would attempt to look up DNS SRV
records for the LDAP server (in order to determine which directory server to
contact) only in the local host's current DNS domain. As a consequence, nslcd
could not search for an LDAP server in a different domain. With this update, the
DNS domain which is used in the lookup can now be specified by providing a value
in the form "DNS:domainname". (BZ#730309)
All users of nss-pam-ldapd are advised to upgrade to this updated package, which
fixes these bugs and adds this enhancement.
Solution
Before applying this update, make sure all previously-released errata relevant
to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259
Affected Products
- Red Hat Enterprise Linux Server 6 x86_64
- Red Hat Enterprise Linux Server 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 i386
- Red Hat Enterprise Linux Workstation 6 x86_64
- Red Hat Enterprise Linux Workstation 6 i386
- Red Hat Enterprise Linux Desktop 6 x86_64
- Red Hat Enterprise Linux Desktop 6 i386
- Red Hat Enterprise Linux for IBM z Systems 6 s390x
- Red Hat Enterprise Linux for Power, big endian 6 ppc64
- Red Hat Enterprise Linux for Scientific Computing 6 x86_64
- Red Hat Enterprise Linux Server from RHUI 6 x86_64
- Red Hat Enterprise Linux Server from RHUI 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6 s390x
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x
Fixes
- BZ - 706454 - upgrade clears config file
- BZ - 706860 - 2 digits login names no seen after upgrading to nss-pam-ldapd-0.7.5-7
- BZ - 720230 - nslcd truncates large gid numbers
- BZ - 737496 - test_common: test_isvalidname failed
- BZ - 741362 - Large UID values can overflow on 32bit architectures
CVEs
(none)
References
(none)
Red Hat Enterprise Linux Server 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux Workstation 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux Desktop 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux for IBM z Systems 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
s390x | |
nss-pam-ldapd-0.7.5-14.el6.s390.rpm | SHA-256: 0fbe3ee5a6acc16fcc2a108f3820496ea9983f7aa0c29c18b6448cc55062f96d |
nss-pam-ldapd-0.7.5-14.el6.s390x.rpm | SHA-256: 4f46189fed7c83418ac36006dd7fac06d48a1c16de850b3104665508afe263f9 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390.rpm | SHA-256: bbca95ec108043a84442c0f16cc2a90e159975e0ca9f6adf1657a9e2e6391995 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390x.rpm | SHA-256: 018a2b111964ab5354b45e5801d97e77391e7d8ed1ad563baa4353731ee269c9 |
Red Hat Enterprise Linux for Power, big endian 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
ppc64 | |
nss-pam-ldapd-0.7.5-14.el6.ppc.rpm | SHA-256: a24af10d74586fec2d7e1fde56c23b51f989771c9df0b836e88773434734de98 |
nss-pam-ldapd-0.7.5-14.el6.ppc64.rpm | SHA-256: 2445743baca21246b67275986332a19b75ca9d8945cd2c1f297cf93b3b22ca8a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.ppc.rpm | SHA-256: 44f827fa15f7633f3bb7d181528e7ba51ddcb3c27a70f9d80f9a3cc3715d8f65 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.ppc64.rpm | SHA-256: 5486fb962515801019b632d7dadd4b2850efaecd1e8fc8cfbb1f1fe9380c52df |
Red Hat Enterprise Linux for Scientific Computing 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
Red Hat Enterprise Linux Server from RHUI 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
s390x | |
nss-pam-ldapd-0.7.5-14.el6.s390.rpm | SHA-256: 0fbe3ee5a6acc16fcc2a108f3820496ea9983f7aa0c29c18b6448cc55062f96d |
nss-pam-ldapd-0.7.5-14.el6.s390x.rpm | SHA-256: 4f46189fed7c83418ac36006dd7fac06d48a1c16de850b3104665508afe263f9 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390.rpm | SHA-256: bbca95ec108043a84442c0f16cc2a90e159975e0ca9f6adf1657a9e2e6391995 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390x.rpm | SHA-256: 018a2b111964ab5354b45e5801d97e77391e7d8ed1ad563baa4353731ee269c9 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
x86_64 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-0.7.5-14.el6.x86_64.rpm | SHA-256: 60bb5f9924eb3f74cf5c977d746623207b3d4e96d0ded0a3b97ec269187ee86a |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.x86_64.rpm | SHA-256: 47631fecfd55add23d9f9bae3e32d6611d25ecb19661c274756bcb0001b81893 |
i386 | |
nss-pam-ldapd-0.7.5-14.el6.i686.rpm | SHA-256: 3e9d4d3fe58aec53290f2e584c99bb9b5cddad20b8f848f3215fd63f9d63a4b8 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.i686.rpm | SHA-256: 34e07733d423b0f65bd52486be99ac10b25c618c48a22c1e06c87aaceaf9a9fe |
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6
SRPM | |
---|---|
nss-pam-ldapd-0.7.5-14.el6.src.rpm | SHA-256: 3a3e206c58deff56d425fcd62d7aeaec340a8ec2489a58478367ca80a386d48d |
s390x | |
nss-pam-ldapd-0.7.5-14.el6.s390.rpm | SHA-256: 0fbe3ee5a6acc16fcc2a108f3820496ea9983f7aa0c29c18b6448cc55062f96d |
nss-pam-ldapd-0.7.5-14.el6.s390x.rpm | SHA-256: 4f46189fed7c83418ac36006dd7fac06d48a1c16de850b3104665508afe263f9 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390.rpm | SHA-256: bbca95ec108043a84442c0f16cc2a90e159975e0ca9f6adf1657a9e2e6391995 |
nss-pam-ldapd-debuginfo-0.7.5-14.el6.s390x.rpm | SHA-256: 018a2b111964ab5354b45e5801d97e77391e7d8ed1ad563baa4353731ee269c9 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.