UbuntuUpdates.org

Package "python3-ldap"

Name: python3-ldap

Description:

LDAP interface module for Python3

Latest version: 3.4.4-1ubuntu0.25.10.2
Release: questing (25.10)
Level: updates
Repository: main
Head package: python-ldap
Homepage: https://www.python-ldap.org

Links


Download "python3-ldap"


Other versions of "python3-ldap" in Questing

Repository Area Version
base main 3.4.4-1build3
security main 3.4.4-1ubuntu0.25.10.1
proposed main 3.4.4-1ubuntu0.25.10.2

Changelog

Version: 3.4.4-1ubuntu0.25.10.2 2026-02-11 04:07:53 UTC

  python-ldap (3.4.4-1ubuntu0.25.10.2) questing; urgency=medium

  * d/t/{startserver,upstream}: fix slapd apparmor access to test directory
    (LP: #2130351)
    - d/t/apparmor.sh: ignore apparmor control failures on Ubuntu+armhf
      (LP: #2008393)

 -- Jonas Jelten <email address hidden> Tue, 20 Jan 2026 11:53:15 +0100

Source diff to previous version
2130351 openldap apparmor profile denies access to test files in /tmp/
2008393 armhf dep8 failure due to restrictions changing apparmor profile status

Version: 3.4.4-1ubuntu0.25.10.1 2025-10-20 22:12:08 UTC

  python-ldap (3.4.4-1ubuntu0.25.10.1) questing-security; urgency=medium

  * SECURITY UPDATE: Improper special character escape when supplying
    non-string data types.
    - debian/patches/CVE-2025-61911.patch: Raise exception when type is not str
      in Lib/ldap/filter.py.
    - CVE-2025-61911
  * SECURITY UPDATE: Denial of service through improperly escaped null byte.
    - debian/patches/CVE-2025-61912.patch: Change NULL byte escape from \\\000
      to \\00 in Lib/ldap/dn.py.
    - CVE-2025-61912

 -- Hlib Korzhynskyy <email address hidden> Wed, 15 Oct 2025 10:54:05 -0230

CVE-2025-61911 python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter
CVE-2025-61912 python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x



About   -   Send Feedback to @ubuntu_updates