UbuntuUpdates.org

Package "python-ldap"

Name: python-ldap

Description:

LDAP interface module for Python

Latest version: 3.0.0-1ubuntu0.2
Release: bionic (18.04)
Level: security
Repository: main
Homepage: https://www.python-ldap.org

Links


Download "python-ldap"


Other versions of "python-ldap" in Bionic

Repository Area Version
base main 3.0.0-1
base universe 3.0.0-1
security universe 3.0.0-1ubuntu0.2
updates universe 3.0.0-1ubuntu0.2
updates main 3.0.0-1ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.0.0-1ubuntu0.2 2022-07-11 17:07:11 UTC

  python-ldap (3.0.0-1ubuntu0.2) bionic-security; urgency=medium

  * SECURITY UPDATE: Regular Expression DoS
    - debian/patches/CVE-2021-46823-pre.patch: get rid of
      expected failures in tokenizer tests in Lib/ldap/schema/tokenizer.py,
      Tests/t_ldap_schema_tokenizer.py.
    - debian/patches/CVE-2021-46823.patch: fix ReDoS in
      regex in Lib/ldap/schema/tokenizer.py.
    - CVE-2021-46823

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 04 Jul 2022 13:38:48 -0300

CVE-2021-46823 python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular express



About   -   Send Feedback to @ubuntu_updates