UbuntuUpdates.org

Package "openldap"

Name: openldap

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • OpenLDAP utilities
  • OpenLDAP libraries
  • OpenLDAP common files for libraries
  • OpenLDAP development libraries

Latest version: 2.4.49+dfsg-2ubuntu1.10
Release: focal (20.04)
Level: updates
Repository: main

Links



Other versions of "openldap" in Focal

Repository Area Version
base main 2.4.49+dfsg-2ubuntu1
base universe 2.4.49+dfsg-2ubuntu1
security main 2.4.49+dfsg-2ubuntu1.10
security universe 2.4.49+dfsg-2ubuntu1.10
updates universe 2.4.49+dfsg-2ubuntu1.10

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.4.49+dfsg-2ubuntu1.10 2024-01-30 15:08:37 UTC

  openldap (2.4.49+dfsg-2ubuntu1.10) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via lack of strdup return code checking
    - debian/patches/CVE-2023-2953-1.patch: check for ber_strdup failure in
      libraries/libldap/fetch.c.
    - debian/patches/CVE-2023-2953-2.patch: check for strdup failure in
      libraries/libldap/url.c.
    - CVE-2023-2953

 -- Marc Deslauriers <email address hidden> Thu, 25 Jan 2024 13:43:43 -0500

Source diff to previous version
CVE-2023-2953 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Version: 2.4.49+dfsg-2ubuntu1.9 2022-05-17 16:06:41 UTC

  openldap (2.4.49+dfsg-2ubuntu1.9) focal-security; urgency=medium

  * SECURITY UPDATE: SQL injection in experimental back-sql backend
    - debian/patches/CVE-2022-29155.patch: escape filter values in
      servers/slapd/back-sql/search.c.
    - CVE-2022-29155

 -- Marc Deslauriers <email address hidden> Thu, 12 May 2022 09:11:05 -0400

Source diff to previous version
CVE-2022-29155 In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s

Version: 2.4.49+dfsg-2ubuntu1.8 2021-04-26 17:06:19 UTC

  openldap (2.4.49+dfsg-2ubuntu1.8) focal; urgency=medium

  * d/p/ITS-8650-loop-on-incomplete-TLS-handshake.patch:
    Import upstream patch to properly retry gnutls_handshake() after it
    returns GNUTLS_E_AGAIN. (ITS#8650) (LP: #1921562)

 -- Utkarsh Gupta <email address hidden> Thu, 08 Apr 2021 09:52:01 +0530

Source diff to previous version
1921562 Intermittent hangs during ldap_search_ext when TLS enabled

Version: 2.4.49+dfsg-2ubuntu1.7 2021-02-22 17:06:23 UTC

  openldap (2.4.49+dfsg-2ubuntu1.7) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via malicious packet
    - debian/patches/CVE-2021-27212.patch: fix issuerAndThisUpdateCheck in
      servers/slapd/schema_init.c.
    - CVE-2021-27212

 -- Marc Deslauriers <email address hidden> Thu, 18 Feb 2021 09:22:15 -0500

Source diff to previous version
CVE-2021-27212 In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a craft

Version: 2.4.49+dfsg-2ubuntu1.6 2021-02-08 15:07:33 UTC

  openldap (2.4.49+dfsg-2ubuntu1.6) focal-security; urgency=medium

  * SECURITY UPDATE: integer underflow in Certificate Exact Assertion
    processing
    - debian/patches/CVE-2020-36221-1.patch: fix serialNumberAndIssuerCheck
      in servers/slapd/schema_init.c.
    - debian/patches/CVE-2020-36221-2.patch: fix serialNumberAndIssuerCheck
      in servers/slapd/schema_init.c.
    - CVE-2020-36221
  * SECURITY UPDATE: assert failure in saslAuthzTo validation
    - debian/patches/CVE-2020-36222-1.patch: remove saslauthz asserts in
      servers/slapd/saslauthz.c.
    - debian/patches/CVE-2020-36222-2.patch: fix debug msg in
      servers/slapd/saslauthz.c.
    - CVE-2020-36222
  * SECURITY UPDATE: crash in Values Return Filter control handling
    - debian/patches/CVE-2020-36223.patch: fix vrfilter double-free in
      servers/slapd/controls.c.
    - CVE-2020-36223
  * SECURITY UPDATE: DoS in saslAuthzTo processing
    - debian/patches/CVE-2020-36224-1.patch: use ch_free on normalized DN
      in servers/slapd/saslauthz.c.
    - debian/patches/CVE-2020-36224-2.patch: use slap_sl_free in prev
      commit in servers/slapd/saslauthz.c.
    - CVE-2020-36224
  * SECURITY UPDATE: DoS in saslAuthzTo processing
    - debian/patches/CVE-2020-36225.patch: fix AVA_Sort on invalid RDN in
      servers/slapd/dn.c.
    - CVE-2020-36225
  * SECURITY UPDATE: DoS in saslAuthzTo processing
    - debian/patches/CVE-2020-36226.patch: fix slap_parse_user in
      servers/slapd/saslauthz.c.
    - CVE-2020-36226
  * SECURITY UPDATE: infinite loop in cancel_extop Cancel operation
    - debian/patches/CVE-2020-36227.patch: fix cancel exop in
      servers/slapd/cancel.c.
    - CVE-2020-36227
  * SECURITY UPDATE: DoS in Certificate List Exact Assertion processing
    - debian/patches/CVE-2020-36228.patch: fix issuerAndThisUpdateCheck in
      servers/slapd/schema_init.c.
    - CVE-2020-36228
  * SECURITY UPDATE: DoS in X.509 DN parsing in ad_keystring
    - debian/patches/CVE-2020-36229.patch: add more checks to
      ldap_X509dn2bv in libraries/libldap/tls2.c.
    - CVE-2020-36229
  * SECURITY UPDATE: DoS in X.509 DN parsing in ber_next_element
    - debian/patches/CVE-2020-36230.patch: check for invalid BER after RDN
      count in libraries/libldap/tls2.c.
    - CVE-2020-36230

 -- Marc Deslauriers <email address hidden> Tue, 02 Feb 2021 11:06:34 -0500

CVE-2020-36221 An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in de
CVE-2020-36222 A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of servic
CVE-2020-36223 A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service
CVE-2020-36224 A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial
CVE-2020-36225 A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of servic
CVE-2020-36226 A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in
CVE-2020-36227 A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of s
CVE-2020-36228 An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting
CVE-2020-36229 A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in deni
CVE-2020-36230 A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, result



About   -   Send Feedback to @ubuntu_updates