Summary: | <net-nds/openldap-2.4.50: Denial of service via nested boolean expressions in LDAP search filters (CVE-2020-12243) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | ldap-bugs |
Priority: | Normal | Flags: | nattka:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugs.openldap.org/show_bug.cgi?id=9202 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
=net-nds/openldap-2.4.50 amd64 arm arm64 hppa ppc ppc64 s390 sparc x86
|
Runtime testing required: | --- |
Bug Depends on: | |||
Bug Blocks: | 641576 |
Description
Sam James
![]() ![]() ![]() ![]() @maintainer(s), please bump to 2.4.50. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4bf2f1709bbb8b087c56a2e01ce735d0dac58c2b commit 4bf2f1709bbb8b087c56a2e01ce735d0dac58c2b Author: Robin H. Johnson <robbat2@gentoo.org> AuthorDate: 2020-05-02 23:12:26 +0000 Commit: Robin H. Johnson <robbat2@gentoo.org> CommitDate: 2020-05-02 23:12:26 +0000 net-nds/openldap: bump for security CVE-2020-12243 Also update mirrors to use HTTPS/HTTPS, because upstream's official download URL is a FTP site which seems to be broken. Bug: https://bugs.gentoo.org/641576 Bug: https://bugs.gentoo.org/719960 Signed-off-by: Robin H. Johnson <robbat2@gentoo.org> net-nds/openldap/Manifest | 1 + net-nds/openldap/openldap-2.4.50.ebuild | 907 ++++++++++++++++++++++++++++++++ 2 files changed, 908 insertions(+) arches, please test and stabilize. FEATURES='test' USE='use -minimal' emerge =openldap-2.4.50 Unable to check for sanity:
> disallowed package spec (only = allowed): net-nds/openldap
arm stable amd64 stable sparc stable arm64 stable hppa stable s390 stable x86 stable ppc stable ppc64 stable GLSA vote: no. |