The vendor explicitly identifies these products or versions as containing the fix.
- erlang27-main@aarch64 as a component of Red Hat Hardened Images
- erlang27-main@src as a component of Red Hat Hardened Images
- erlang27-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in eldap, a component of Erlang/OTP. A malicious or compromised Lightweight Directory Access Protocol (LDAP) server could exploit this vulnerability by returning a referral Uniform Resource Locator (URL) with an excessively long port number. This unbounded port component is then processed by the eldap:parse_port/2 function, leading to a significant increase in processing time due to arbitrary-precision arithmetic. This can degrade the availability of the affected system, resulting in a Denial of Service (DoS).
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
