UbuntuUpdates.org

Package "python3-pyldap"

Name: python3-pyldap

Description:

LDAP interface module for Python 3.x - transition package

Latest version: 3.2.0-4ubuntu7.1
Release: jammy (22.04)
Level: security
Repository: universe
Head package: python-ldap
Homepage: https://www.python-ldap.org

Links


Download "python3-pyldap"


Other versions of "python3-pyldap" in Jammy

Repository Area Version
base universe 3.2.0-4ubuntu7
updates universe 3.2.0-4ubuntu7.1

Changelog

Version: 3.2.0-4ubuntu7.1 2022-07-11 17:07:17 UTC

  python-ldap (3.2.0-4ubuntu7.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Regular Expression DoS
    - debian/patches/CVE-2021-46823-pre.patch: get rid of
      expected failures in tokenizer tests in Lib/ldap/schema/tokenizer.py,
      Tests/t_ldap_schema_tokenizer.py.
    - debian/patches/CVE-2021-46823.patch: fix ReDoS in
      regex in Lib/ldap/schema/tokenizer.py.
    - CVE-2021-46823

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 04 Jul 2022 13:21:22 -0300

CVE-2021-46823 python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular express



About   -   Send Feedback to @ubuntu_updates