[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
RE: OpenLDAP 2.4.45 possible denial of service vulnerability?
- To: <hbohnenkamp@united-internet.de>, <openldap-technical@openldap.org>
- Subject: RE: OpenLDAP 2.4.45 possible denial of service vulnerability?
- From: <Juergen.Sprenger@swisscom.com>
- Date: Wed, 30 Jan 2019 11:52:35 +0000
- Accept-language: en-US, de-CH
- Content-language: en-US
- In-reply-to: <20190130112303.GA31384@united-internet.de>
- Msip_labels: MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Enabled=True; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_SiteId=364e5b87-c1c7-420d-9bee-c35d19b557a1; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Owner=Juergen.Sprenger@swisscom.com; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_SetDate=2019-01-30T11:52:34.3009365Z; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Name=C2 Internal; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Application=Microsoft Azure Information Protection; MSIP_Label_2e1fccfb-80ca-4fe1-a574-1516544edb53_Extended_MSFT_Method=Automatic; Sensitivity=C2 Internal
- References: <88b17ef74a674a3ab355d93abf9d6c93@swisscom.com> <829dcca43782435dbdd8254cf261a5d3@swisscom.com> <20190130112303.GA31384@united-internet.de>
- Thread-index: AdS4fbsO93wWUGwITBWlf20mYQhSRQABuH9QAABKzIAAAr5TMA==
- Thread-topic: OpenLDAP 2.4.45 possible denial of service vulnerability?
Hi Henrik,
Many thanks for Your advice,
- Yes, we started using mdb-backend and did not use it before.
- LDAP tree is not very large, a slapcat dump has about 1.050 Million lines and less than 50'000 dn entries.
- LDAP tree contains attributes 21661 of type aliasedObjectName
- Yes, alias-dereferencing is used and set to always. Clients should not, but may do searches using "sub" instead of "one" .
I will check whether using hdb will mitigate the problem.
Jürgen
-----Original Message-----
From: Henrik Bohnenkamp [mailto:hbohnenkamp@united-internet.de]
Sent: Mittwoch, 30. Januar 2019 12:23
To: Sprenger Jürgen, INI-ONE-CIS-SDI-HES <Juergen.Sprenger@swisscom.com>
Subject: Re: OpenLDAP 2.4.45 possible denial of service vulnerability?
On Wed, Jan 30, 2019 at 10:17:47AM +0000, Juergen.Sprenger@swisscom.com wrote:
Hi Jürgen,
if you can answer all of the following questions with "yes", you might have the problem described in ITS#8875/ITS#7657
(http://www.openldap.org/its/index.cgi/Incoming?id=8875;selectid=8875):
- with the upgrade to 2.4.45, you started to use the mdb-backend, and
did not use it before
- your LDAP tree is large (> 1 Million entries)
- the LDAP tree contains many alias objects (> 64k )
- the clients causing the trouble make searches with scope "sub", and alias-dereferencing
set to "always"
That's essential the 4 conditions that lead to a problem at my organisation similar to the one you described. Workaround was to go back to the hdb backend.
Henrik
--
Henrik Bohnenkamp