Accepted: openldap2.3 2.4.7-5ubuntu2 (source)
Emanuele Gentili
emgent at emanuele-gentili.com
Mon Mar 3 10:45:22 GMT 2008
Accepted:
OK: openldap2.3_2.4.7.orig.tar.gz
OK: openldap2.3_2.4.7-5ubuntu2.diff.gz
OK: openldap2.3_2.4.7-5ubuntu2.dsc
-> Component: main Section: net
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 02 Mar 2008 16:34:30 +0100
Source: openldap2.3
Binary: slapd ldap-utils libldap-2.4-2 libldap-2.4-2-dbg libldap2-dev slapd-dbg
Architecture: source
Version: 2.4.7-5ubuntu2
Distribution: hardy
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Emanuele Gentili <emgent at emanuele-gentili.com>
Description:
ldap-utils - OpenLDAP utilities
libldap-2.4-2 - OpenLDAP libraries
libldap-2.4-2-dbg - Debugging information for OpenLDAP libraries
libldap2-dev - OpenLDAP development libraries
slapd - OpenLDAP server (slapd)
slapd-dbg - Debugging information for the OpenLDAP server (slapd)
Launchpad-Bugs-Fixed: 197077
Changes:
openldap2.3 (2.4.7-5ubuntu2) hardy; urgency=low
.
* SECURITY UPDATE:
+ debian/patches/SECURITY_CVE-2008-0658.patch (LP: #197077)
slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39
allows remote authenticated users to cause a denial of service (daemon crash)
via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related
issue to CVE-2007-6698.
.
* References
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0658
- http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358
Files:
d364babf6bead87d47bf4c99a0b09100 1509 net optional openldap2.3_2.4.7-5ubuntu2.dsc
19a9be5caa6bbb66ea15bae84741901c 144460 net optional openldap2.3_2.4.7-5ubuntu2.diff.gz
Original-Maintainer: Debian OpenLDAP Maintainers <pkg-openldap-devel at lists.alioth.debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHy9YnDecnbV4Fd/IRAttlAKDk0W4tWeel9S0R08Q6nSsBRj8fGgCgooKS
qR01KfPNtSfL9RHfz6YH3U4=
=OebN
-----END PGP SIGNATURE-----
More information about the Hardy-changes
mailing list