ELSA-2021-3807

ELSA-2021-3807 - 389-ds-base security and bug fix update

Type:SECURITY
Severity:LOW
Release Date:2021-10-13

Description


[1.3.10.2-13]
- Bump version to 1.3.10.2-13
- Resolves: Bug 2005399 - Internal unindexed searches in syncrepl
- Resolves: Bug 2005432 - CVE-2021-3652 389-ds:1.4/389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
- Resolves: Bug 2005434 - ACIs are being evaluated against the Replication Manager account in a replication context.
- Resolves: Bug 2005435 - A connection can be erroneously flagged as replication conn during evaluation of an aci with ip bind rule


Related CVEs


CVE-2021-3652

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) 389-ds-base-1.3.10.2-13.el7_9.src.rpm7ca4e8ccbeda066630bb39efe7678578-
389-ds-base-1.3.10.2-13.el7_9.aarch64.rpmecdbf688ee973c32b0dbcee4a8d74a4d-
389-ds-base-devel-1.3.10.2-13.el7_9.aarch64.rpmc4f1f6a2cab31a8ca58b729a1b01ed7b-
389-ds-base-libs-1.3.10.2-13.el7_9.aarch64.rpm559c7cf3b6734eec78b8306a788333a7-
389-ds-base-snmp-1.3.10.2-13.el7_9.aarch64.rpm4aaff5aa28fc0b704ecc344042026e03-
Oracle Linux 7 (x86_64) 389-ds-base-1.3.10.2-13.el7_9.src.rpm7ca4e8ccbeda066630bb39efe7678578-
389-ds-base-1.3.10.2-13.el7_9.x86_64.rpm5376ed28b4acb26200679388b540b0b5-
389-ds-base-devel-1.3.10.2-13.el7_9.x86_64.rpm8c47fc7ead28601c6c7869432de04700-
389-ds-base-libs-1.3.10.2-13.el7_9.x86_64.rpmbd31a7f275da53a776abc9e5b2304694-
389-ds-base-snmp-1.3.10.2-13.el7_9.x86_64.rpm045ef24771ffb0a0b99b0876611f2775-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete