Accepted: openldap2.3 2.4.7-5ubuntu2 (source)

Emanuele Gentili emgent at emanuele-gentili.com
Mon Mar 3 10:45:22 GMT 2008


Accepted:
 OK: openldap2.3_2.4.7.orig.tar.gz
 OK: openldap2.3_2.4.7-5ubuntu2.diff.gz
 OK: openldap2.3_2.4.7-5ubuntu2.dsc
     -> Component: main Section: net

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 02 Mar 2008 16:34:30 +0100
Source: openldap2.3
Binary: slapd ldap-utils libldap-2.4-2 libldap-2.4-2-dbg libldap2-dev slapd-dbg
Architecture: source
Version: 2.4.7-5ubuntu2
Distribution: hardy
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Emanuele Gentili <emgent at emanuele-gentili.com>
Description: 
 ldap-utils - OpenLDAP utilities
 libldap-2.4-2 - OpenLDAP libraries
 libldap-2.4-2-dbg - Debugging information for OpenLDAP libraries
 libldap2-dev - OpenLDAP development libraries
 slapd      - OpenLDAP server (slapd)
 slapd-dbg  - Debugging information for the OpenLDAP server (slapd)
Launchpad-Bugs-Fixed: 197077
Changes: 
 openldap2.3 (2.4.7-5ubuntu2) hardy; urgency=low
 .
   * SECURITY UPDATE:
    + debian/patches/SECURITY_CVE-2008-0658.patch (LP: #197077)
      slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39
      allows remote authenticated users to cause a denial of service (daemon crash)
      via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related
      issue to CVE-2007-6698.
 .
   * References
    - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0658
    - http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358
Files: 
 d364babf6bead87d47bf4c99a0b09100 1509 net optional openldap2.3_2.4.7-5ubuntu2.dsc
 19a9be5caa6bbb66ea15bae84741901c 144460 net optional openldap2.3_2.4.7-5ubuntu2.diff.gz
Original-Maintainer: Debian OpenLDAP Maintainers <pkg-openldap-devel at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHy9YnDecnbV4Fd/IRAttlAKDk0W4tWeel9S0R08Q6nSsBRj8fGgCgooKS
qR01KfPNtSfL9RHfz6YH3U4=
=OebN
-----END PGP SIGNATURE-----





More information about the Hardy-changes mailing list