ELSA-2008-0715

ELSA-2008-0715 - nss_ldap security and bug fix update

Type:SECURITY
Severity:LOW
Release Date:2008-08-01

Description


[253-5]
- build with strict-aliasing disabled, because pam_ldap breaks strict-aliasing
rules without it (tools)

[253-4]
- block SIGPIPE in the atfork handler, so that it doesnt trip up when
attempting to drop a connection to the server (#448833)

[253-3]
- add patch to make netgroup enumeration fail due to lack of entries in
setnetgrent(), rather than in getnetgrent(), to match how other mechanisms
work (Jose Plans, #253997)

[253-2]
- add fix for not double-freeing the result list when we try to initialize an
internal enumeration context while we have one active (#233382)

[253-1]
- rebase to nss_ldap 253 (#401731)
- fixes leftover lock problem in nss_initgroups_ignoreusers handling (#429101)
- fixes re-use of connections across fork() (#155187)


Related CVEs


CVE-2007-5794

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) nss_ldap-253-5.el4.src.rpma4b0f452bc40b1b43857f9b941a3b9e9ELBA-2011-0239
nss_ldap-253-5.el4.i386.rpm1606c33685a1f699506caf027b313500ELBA-2011-0239
Oracle Linux 4 (ia64) nss_ldap-253-5.el4.src.rpma4b0f452bc40b1b43857f9b941a3b9e9ELBA-2011-0239
nss_ldap-253-5.el4.i386.rpm1606c33685a1f699506caf027b313500ELBA-2011-0239
nss_ldap-253-5.el4.ia64.rpme8797156a8ccaad10f652fb4f5eb6a8cELBA-2011-0239
Oracle Linux 4 (x86_64) nss_ldap-253-5.el4.src.rpma4b0f452bc40b1b43857f9b941a3b9e9ELBA-2011-0239
nss_ldap-253-5.el4.i386.rpm1606c33685a1f699506caf027b313500ELBA-2011-0239
nss_ldap-253-5.el4.x86_64.rpmb8e1349ee51398636ca93b6109a659c1ELBA-2011-0239



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete