[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#777513: unblock: openldap/2.4.40-4 (pre-approval)



On Sun, Feb  8, 2015 at 17:59:00 -0800, Ryan Tandy wrote:

> Package: release.debian.org
> Severity: normal
> User: release.debian.org@packages.debian.org
> Usertags: unblock
> 
> Hi,
> 
> We would like to fix two recently-discovered upstream bugs in openldap 
> that allow an unauthenticated remote user to crash the LDAP server.
> 
> #776988, CVE-2015-1545: If the deref overlay is enabled (by default, it 
> is not), the query "ldapsearch -E deref=member:" crashes slapd via a 
> NULL pointer dereference.
> 
> #776991, CVE-2015-1546: The query "ldapsearch -E 'mv=(cn={*)(sn=*)'" 
> crashes slapd via a double free (regression in 2.4.40).
> 
> The deref overlay is not widely used, but #776991 affects all slapd 
> users.
> 
> May we upload with these changes?
> 
Please do.

Cheers,
Julien

Attachment: signature.asc
Description: Digital signature


Reply to: