ELSA-2016-2765

ELSA-2016-2765 - 389-ds-base security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2016-11-15

Description


[1.2.11.15-84]
- Release 1.2.11.15-84
- Resolves: #1376676 - Backport AES storage scheme plugin (DS 47462)

[1.2.11.15-83]
- Release 1.2.11.15-83
- Resolves: #1376676 - Backport AES storage scheme plugin (DS 47462)

[1.2.11.15-82]
- Release 1.2.11.15-82
- Resolves: #1376676 - Backport AES storage scheme plugin (DS 47462)

[1.2.11.15-81]
- Release 1.2.11.15-81
- Resolves: #Bug 1381153 - Crash in import_wait_for_space_in_fifo(). (DS 48960)

[1.2.11.15-80]
- Release 1.2.11.15-80
- Resolves: #1379599 - ns-slapd general protection ip:7f570c56afd5 sp:7f56dc7edce0 error:0 in libc-2.12.so (DS 48944)

[1.2.11.15-79]
- Release 1.2.11.15-79
- Resolves: #1358559 - CVE-2016-4992 389-ds-base: Information disclosure via repeated use of LDAP ADD operation
- Resolves: #1376676 - Backport AES storage scheme plugin (DS 47462, 48862, 48243, 48777)
- Resolves: #1354331 - Replication changelog can incorrectly skip over updates
- Resolves: #1374588 - EASY FIX : dereferencing a NULL sr_candidates pointer in ldbm_back_next_search_entry_ext resulted a segfault (DS 47858)

[1.2.11.15-78]
- Release 1.2.11.15-78
- Resolves: #1354331 - Replication changelog can incorrectly skip over updates (DS 48954)
- Resolves: #1361421 - CVE-2016-5416 389-ds-base: ACI readable by anonymous user (DS 48354)
- Resolves: #1360974 - CVE-2016-5405 389-ds-base: Password verification vulnerable to timing attack

[1.2.11.15-77]
- Release 1.2.11.15-77
- Resolves: #1358390 - replication delay when server is configured with multiple replication agreements. (DS 48636)
fixing a backport error

[1.2.11.15-76]
- Release 1.2.11.15-76
- Resolves: #1354331 - Replication changelog can incorrectly skip over updates (DS 48766)
- Resolves: #1358390 - replication delay when server is configured with multiple replication agreements. (DS 48636)


Related CVEs


CVE-2016-4992
CVE-2016-5405
CVE-2016-5416

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) 389-ds-base-1.2.11.15-84.el6_8.src.rpmff8c38100357faa77a611d6ff3755b61ELBA-2018-2407
389-ds-base-1.2.11.15-84.el6_8.i686.rpm0294fe462bf130b6285762c9ab5d3d00ELBA-2018-2407
389-ds-base-devel-1.2.11.15-84.el6_8.i686.rpme6fba9efe18bdb469bcedb00b60c7b5dELBA-2018-2407
389-ds-base-libs-1.2.11.15-84.el6_8.i686.rpmde8fad63a024cab9db6665081693c198ELBA-2018-2407
Oracle Linux 6 (x86_64) 389-ds-base-1.2.11.15-84.el6_8.src.rpmff8c38100357faa77a611d6ff3755b61ELBA-2018-2407
389-ds-base-1.2.11.15-84.el6_8.x86_64.rpm368afafb4aa98cf96a4108be8ff7b2ceELBA-2018-2407
389-ds-base-devel-1.2.11.15-84.el6_8.i686.rpme6fba9efe18bdb469bcedb00b60c7b5dELBA-2018-2407
389-ds-base-devel-1.2.11.15-84.el6_8.x86_64.rpmdd7f913136996e0012b7a765b0e077fcELBA-2018-2407
389-ds-base-libs-1.2.11.15-84.el6_8.i686.rpmde8fad63a024cab9db6665081693c198ELBA-2018-2407
389-ds-base-libs-1.2.11.15-84.el6_8.x86_64.rpmb5583c54cfbe5c42ef6971f325c67fb9ELBA-2018-2407



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete