Описание
ELSA-2012-0899: openldap security and bug fix update (LOW)
[2.4.23-26]
- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)
- fix: memory leak: def_urlpre is not freed (#816168)
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
[2.4.23-25]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
[2.4.23-24]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
- fix: memberof overlay on the frontend database causes server segfault (#730745)
[2.4.23-23]
- security fix: CVE-2012-1164: assertion failure by processing search queries requesting only attributes for particular entry (#813162)
[2.4.23-22]
- fix: libraries leak memory when following referrals (#807363)
[2.4.23-21]
- fix: ldapsearch crashes with invalid parameters (#743781)
- fix: replication (syncrepl) with TLS causes segfault (#783445)
- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)
- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)
- fix: missing options in manual pages of client tools (#745470)
- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)
- fix: slapd segfaults when certificate key cannot be loaded (#796808)
- Jan Synacek jsynacek@redhat.com
- fix: overlay constraint with count option work bad with modify operation (#742163)
- fix: Default SSL certificate bundle is not found by openldap library (#742023)
- fix: Duplicate close() calls in OpenLDAP (#784203)
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
openldap
2.4.23-26.el6
openldap-clients
2.4.23-26.el6
openldap-devel
2.4.23-26.el6
openldap-servers
2.4.23-26.el6
openldap-servers-sql
2.4.23-26.el6
Oracle Linux i686
openldap
2.4.23-26.el6
openldap-clients
2.4.23-26.el6
openldap-devel
2.4.23-26.el6
openldap-servers
2.4.23-26.el6
openldap-servers-sql
2.4.23-26.el6
Связанные CVE
Связанные уязвимости
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a den ...
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.