ELSA-2018-1380

ELSA-2018-1380 - 389-ds-base security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2018-05-14

Description


[1.3.7.5-21]
- Bump version to 1.3.7.5-21
- Resolves: Bug 1559818 - EMBARGOED CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch

[1.3.7.5-20]
- Bump version to 1.3.7.5-20
- Resolves: Bug 1563079 - adjustment of csn_generator can fail so next generated csn can be equal to the most recent one received
- Resolves: Bug 1559764 - memberof fails if group is moved into scope
- Resolves: Bug 1554720 - 'Truncated search results' pop-up appears in user details in WebUI
- Resolves: Bug 1553605 - ipa-server-install fails with Error: Upgrade failed with no such entry
- Resolves: Bug 1559760 - ds-replcheck: add -W option to ask for the password from stdin instead of passing it on command line
- Resolves: Bug 1559464 - replica_write_ruv log a failure even when it succeeds


Related CVEs


CVE-2018-1089

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) 389-ds-base-1.3.7.5-21.el7_5.src.rpm1cd25c27d7fa5f3c8965cf925b0f1f8aELBA-2021-0868
389-ds-base-1.3.7.5-21.el7_5.aarch64.rpmf8b53f222d4277157a40877ae2a2c999ELBA-2021-0868
389-ds-base-devel-1.3.7.5-21.el7_5.aarch64.rpm3ad2e72db7abd6f4a774b789fa97c584ELBA-2021-0868
389-ds-base-libs-1.3.7.5-21.el7_5.aarch64.rpmeda55d2113b797649b088c4415fe1161ELBA-2021-0868
389-ds-base-snmp-1.3.7.5-21.el7_5.aarch64.rpmb087f837efb077e008c645b9e079e6c7ELBA-2021-0868
Oracle Linux 7 (x86_64) 389-ds-base-1.3.7.5-21.el7_5.src.rpm1cd25c27d7fa5f3c8965cf925b0f1f8aELBA-2021-0868
389-ds-base-1.3.7.5-21.el7_5.x86_64.rpmbdb6d45ee3967fb61f5b59465bc5514bELBA-2021-0868
389-ds-base-devel-1.3.7.5-21.el7_5.x86_64.rpm3a7b7ce06f917de977dfa64f2a3c7b37ELBA-2021-0868
389-ds-base-libs-1.3.7.5-21.el7_5.x86_64.rpm72cd6c90df6018d73611e2706083531cELBA-2021-0868
389-ds-base-snmp-1.3.7.5-21.el7_5.x86_64.rpm52ca1ff5ba0177d4a8749c26ec07ffd3ELBA-2021-0868



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete