ELSA-2018-3127

ELSA-2018-3127 - 389-ds-base security, bug fix, and enhancement update

Type:SECURITY
Impact:MODERATE
Release Date:2018-11-05

Description


[1.3.8.4-15]
- Bump version to 1.3.8.4-15
- Resolves: Bug 1624004 - Fix regression in last patch

[1.3.8.4-14]
- Bump version to 1.3.8.4-14
- Resolves: Bug 1624004 - potential denial of service attack

[1.3.8.4-13]
- Bump version to 1.3.8.4-13
- Resolves: Bug 1623949 - Crash in delete_passwdPolicy when persistent search connections are terminated unexpectedly

[1.3.8.4-12]
- Bump version to 1.3.8.4-12
- Resolves: Bug 1616412 - filter optimization fix causes regression(fix reverted)

[1.3.8.4-11]
- Bump version to 1.3.8.4-11
- Resolves: Bug 1614820 - Server crash through modify command with large DN

[1.3.8.4-10]
- Bump verison to 1.3.8.4-10
- Resolves: Bug 1614501 - Disable nunc-stans by default
- Resolves: Bug 1607078 - ldapsearch with server side sort crashes the ldap server

[1.3.8.4-9]
- Bump version to 1.3.8.4-9
- Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user 'dirsrv' if there is an already existing user with the UID/GID 389 on the machine.

[1.3.8.4-8]
- Bump version to 1.3.8.4-8
- Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user 'dirsrv' if there is an already existing user with the UID/GID 389 on the machine.

[1.3.8.4-7]
- Bump version to 1.3.8.4-7
- Resolves: Bug 1595766 - backout this fix for now because it breaks FreeIPA (removed patch file all together)

[1.3.8.4-6]
- Bump version to 1.3.8.4-6
- Resolves: Bug 1595766 - backout this fix for now because it breaks FreeIPA

[1.3.8.4-5]
- Bump version to 1.3.8.4-5
- Resolves: Bug 1595766 - CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default

[1.3.8.4-4]
- Bump version to 1.3.8.4-4
- Resolves: Bug 1597384 - Async operations can hang when the server is running nunc-stans
- Resolves: Bug 1598186 - A search with the scope 'one' returns a non-matching entry
- Resolves: Bug 1598718 - import fails if backend name is 'default'
- Resolves: Bug 1598478 - If a replica is created with a bindDNGroup, this group is taken into account only after bindDNGroupCheckInterval seconds
- Resolves: Bug 1525256 - Invalid SNMP MIB for 389 DS
- Resolves: Bug 1597518 - ds-replcheck command returns traceback errors against ldif files having garbage content when run in offline mode

[1.3.8.4-3]
- Bump version to 1.3.8.4-3
- Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user 'dirsrv' if there is an already existing user with the UID/GID 389 on the machine.

[1.3.8.4-2]
- Bump version to 1.3.8.4-2
- Resolves: Bug 1594484 - setup-ds.pl not able to handle/create the user 'dirsrv' if there is an already existing user with the UID/GID 389 on the machine.

[1.3.8.4-1]
- Bump version to 1.3.8.4-1
- Resolves: Bug 1560653 - Rebase 389-ds-base in RHEL 7.6 to 1.3.8

[1.3.8.2-1]
- Bump version to 1.3.8.2-1
- Resolves: Bug 1560653 - Rebase 389-ds-base in RHEL 7.6 to 1.3.8


Related CVEs


CVE-2018-14648

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (aarch64) 389-ds-base-1.3.8.4-15.el7.src.rpm5076eee6fe5390e06969f9e475c8602fb0665159642f1532354224139712e558ELSA-2024-7434ol7_aarch64_latest
389-ds-base-1.3.8.4-15.el7.src.rpm5076eee6fe5390e06969f9e475c8602fb0665159642f1532354224139712e558ELSA-2024-7434ol7_aarch64_optional_latest
389-ds-base-1.3.8.4-15.el7.aarch64.rpm7ca5cd6f4dde6a25e85bac063fe4f8366d25800d8a4791e9c7042124b4be5ad2ELSA-2024-7434ol7_aarch64_latest
389-ds-base-devel-1.3.8.4-15.el7.aarch64.rpmcb009596fec5567fefe36eeb69c27d2380bf02cacdc98599beeee82ca9ffea31ELSA-2024-7434ol7_aarch64_optional_latest
389-ds-base-libs-1.3.8.4-15.el7.aarch64.rpme5cb9f0f57db46415a28c382c5bb6b8a71b57ca6980ea3604f9f0f5e61d3e1d4ELSA-2024-7434ol7_aarch64_latest
389-ds-base-snmp-1.3.8.4-15.el7.aarch64.rpmff191c8630bbb7afedf3b174cb6a07ab801ba246d09384d767bf605783a19798ELSA-2024-7434ol7_aarch64_optional_latest
Oracle Linux 7 (x86_64) 389-ds-base-1.3.8.4-15.el7.src.rpm5076eee6fe5390e06969f9e475c8602fb0665159642f1532354224139712e558ELSA-2024-7434ol7_x86_64_latest
389-ds-base-1.3.8.4-15.el7.src.rpm5076eee6fe5390e06969f9e475c8602fb0665159642f1532354224139712e558ELSA-2024-7434ol7_x86_64_optional_latest
389-ds-base-1.3.8.4-15.el7.src.rpm5076eee6fe5390e06969f9e475c8602fb0665159642f1532354224139712e558ELSA-2024-7434ol7_x86_64_u6_base
389-ds-base-1.3.8.4-15.el7.x86_64.rpm2f90bf00f40e02684f21432e896bbedc308de8e0aafbb0cf99dc159d15e6dbecELSA-2024-7434ol7_x86_64_latest
389-ds-base-1.3.8.4-15.el7.x86_64.rpm2f90bf00f40e02684f21432e896bbedc308de8e0aafbb0cf99dc159d15e6dbecELSA-2024-7434ol7_x86_64_u6_base
389-ds-base-devel-1.3.8.4-15.el7.x86_64.rpm752e15b6336a19a7cadb818b9418b2fa2a0ea5d49bf160798979c406e4cbc0d5ELSA-2024-7434ol7_x86_64_optional_latest
389-ds-base-libs-1.3.8.4-15.el7.x86_64.rpmfe93e3d5cf3959d7996c075878b31dce1d29776c804485d44476e6eeaaad2c03ELSA-2024-7434ol7_x86_64_latest
389-ds-base-libs-1.3.8.4-15.el7.x86_64.rpmfe93e3d5cf3959d7996c075878b31dce1d29776c804485d44476e6eeaaad2c03ELSA-2024-7434ol7_x86_64_u6_base
389-ds-base-snmp-1.3.8.4-15.el7.x86_64.rpm21002ea28321585aeae99b31f36a6a7057bd8046425531de1d23417593c32f6fELSA-2024-7434ol7_x86_64_optional_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete