[Bug 884163] Re: OpenLDAP "UTF8StringNormalize()" Off-by-One Denial of Service Vulnerability

Launchpad Bug Tracker 884163 at bugs.launchpad.net
Mon Nov 14 21:05:12 UTC 2011


This bug was fixed in the package openldap - 2.4.25-3ubuntu2

---------------
openldap (2.4.25-3ubuntu2) precise; urgency=low

  * SECURITY UPDATE: potential denial of service (LP: #884163)
    - debian/patches/CVE-2011-4079: fix off by one error in
      postalAddressNormalize()
    - CVE-2011-4079
 -- Jamie Strandboge <jamie at ubuntu.com>   Mon, 14 Nov 2011 13:59:56 -0600

** Changed in: openldap (Ubuntu Precise)
       Status: Fix Committed => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-4079

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openldap in Ubuntu.
https://bugs.launchpad.net/bugs/884163

Title:
  OpenLDAP "UTF8StringNormalize()" Off-by-One Denial of Service
  Vulnerability

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/884163/+subscriptions



More information about the Ubuntu-server-bugs mailing list