ELSA-2012-0899

ELSA-2012-0899 - openldap security and bug fix update

Type:SECURITY
Severity:LOW
Release Date:2012-06-27

Description


[2.4.23-26]
- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)
- fix: memory leak: def_urlpre is not freed (#816168)
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-25]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)

[2.4.23-24]
- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
- fix: memberof overlay on the frontend database causes server segfault (#730745)

[2.4.23-23]
- security fix: CVE-2012-1164: assertion failure by processing search queries
requesting only attributes for particular entry (#813162)

[2.4.23-22]
- fix: libraries leak memory when following referrals (#807363)

[2.4.23-21]
- fix: ldapsearch crashes with invalid parameters (#743781)
- fix: replication (syncrepl) with TLS causes segfault (#783445)
- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)
- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)
- fix: missing options in manual pages of client tools (#745470)
- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)
- fix: slapd segfaults when certificate key cannot be loaded (#796808)
- Jan Synacek
+ fix: overlay constraint with count option work bad with modify operation (#742163)
+ fix: Default SSL certificate bundle is not found by openldap library (#742023)
+ fix: Duplicate close() calls in OpenLDAP (#784203)


Related CVEs


CVE-2012-1164

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) openldap-2.4.23-26.el6.src.rpmfab2100ccb1478ae6807ac01e7b279eeELBA-2017-0664
openldap-2.4.23-26.el6.i686.rpmb4cb6c36a188ba0a59dbea849e608ca3ELBA-2017-0664
openldap-clients-2.4.23-26.el6.i686.rpmf00cd76cf774ea19d9fc67c367f73343ELBA-2017-0664
openldap-devel-2.4.23-26.el6.i686.rpm8aa2bf97cb08b42b5205f3cdc10437eeELBA-2017-0664
openldap-servers-2.4.23-26.el6.i686.rpmb097919d72b262bb0f15da649a56504bELBA-2017-0664
openldap-servers-sql-2.4.23-26.el6.i686.rpm818344f4b89e09b360e51ac2dbd7231dELBA-2017-0664
Oracle Linux 6 (x86_64) openldap-2.4.23-26.el6.src.rpmfab2100ccb1478ae6807ac01e7b279eeELBA-2017-0664
openldap-2.4.23-26.el6.i686.rpmb4cb6c36a188ba0a59dbea849e608ca3ELBA-2017-0664
openldap-2.4.23-26.el6.x86_64.rpmb9cd4a280c9890309a4f8d377cce5322ELBA-2017-0664
openldap-clients-2.4.23-26.el6.x86_64.rpmdc4f0337c8eb53858cfb8425085f60e2ELBA-2017-0664
openldap-devel-2.4.23-26.el6.i686.rpm8aa2bf97cb08b42b5205f3cdc10437eeELBA-2017-0664
openldap-devel-2.4.23-26.el6.x86_64.rpm7bbaee1ac29f660245df953fb494e051ELBA-2017-0664
openldap-servers-2.4.23-26.el6.x86_64.rpmc223bfdc1417b7cec200a1fd35fe63c6ELBA-2017-0664
openldap-servers-sql-2.4.23-26.el6.x86_64.rpm19c87a9205d5a2323991e4688e00f424ELBA-2017-0664



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete