ELSA-2024-3047

ELSA-2024-3047 - 389-ds:1.4 security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-05-24

Description


[1.4.3.39-3]
- Bump version to 1.4.3.39-3
- Resolves: RHEL-19240 - RFE Add PROXY protocol support to 389-ds-base via confiuration item - similar to Postfix

[1.4.3.39-2]
- Bump version to 1.4.3.39-2
- Resolves: RHEL-23209 - CVE-2024-1062 389-ds:1.4/389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
- Resolves: RHEL-5390 - schema-compat-plugin expensive with automember rebuild
- Resolves: RHEL-5135 - crash in sync_update_persist_op() of content sync plugin

[1.4.3.39-1]
- Bump version to 1.4.3.39-1
- Resolves: RHEL-19028 - Rebase 389-ds-base in RHEL 8.10 to 1.4.3.39
- Resolves: RHEL-19240 - [RFE] Add PROXY protocol support to 389-ds-base
- Resolves: RHEL-5143 - SELinux labeling for dirsrv files seen during ipa install/uninstall should be moved to DEBUG.
- Resolves: RHEL-5107 - bdb_start - Detected Disorderly Shutdown directory server is not starting
- Resolves: RHEL-16338 - ns-slapd crash in slapi_attr_basetype
- Resolves: RHEL-14025 - After an upgrade the LDAP server won't start if nsslapd-conntablesize is present in the dse.ldif file.

[1.4.3.38-1]
- Bump version to 1.4.3.38-1
- Resolves: RHEL-19028 - Rebase 389-ds-base in RHEL 8.10 to 1.4.3.38

[1.4.3.37-1]
- Bump versionto 1.4.3.37-1
- Resolves: rhbz#2224505 - Paged search impacts performance
- Resolves: rhbz#2220890 - healthcheck tool needs to be updates for new default password storage scheme
- Resolves: rhbz#2218235 - python3-lib389: Python tarfile extraction needs change to avoid a warning
- Resolves: rhbz#2210491 - dtablesize being set to soft maxfiledescriptor limit causing massive slowdown in large enviroments.
- Resolves: rhbz#2149967 - SELinux labeling for dirsrv files seen during ipa install/uninstall should be moved to DEBUG

[1.4.3.36-2]
- Bump version to 1.4.3.36-2
- Resolves: rhbz#2220890 - healthcheck tool needs to be updates for new default password storage scheme

[1.4.3.36-1]
- Bump version to 1.4.3.36-1
- Resolves: rhbz#2188628 - Rebase 389-ds-base in RHEL 8.9 to 1.4.3.36

[1.4.3.35-1]
- Bump version to 1.4.3.35-1
- Resolves: rhbz#2188628 - Rebase 389-ds-base in RHEL 8.9 to 1.4.3.35

[1.4.3.32-1]
- Bump version to 1.4.3.32-1
- Resolves: Bug 2098138 - broken nsslapd-subtree-rename-switch option in rhds11
- Resolves: Bug 2119063 - entryuuid fixup tasks fails because entryUUID is not mutable
- Resolves: Bug 2136610 - [RFE] Add 'cn' attribute to IPA audit logs
- Resolves: Bug 2142638 - pam mutex lock causing high etimes, affecting red hat internal sso
- Resolves: Bug 2096795 - [RFE] Support ECDSA private keys for TLS


Related CVEs


CVE-2024-1062

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) 389-ds-base-1.4.3.39-3.module+el8.10.0+90328+4f014c15.src.rpmd2355eee36cc4012f1482d01d67f64ac-ol8_aarch64_appstream
389-ds-base-1.4.3.39-3.module+el8.10.0+90328+4f014c15.aarch64.rpm9a54c82eb1068b446d3b55bc0b4bb816-ol8_aarch64_appstream
389-ds-base-devel-1.4.3.39-3.module+el8.10.0+90328+4f014c15.aarch64.rpm88d1d4400dc3d29605540a2461116e6e-ol8_aarch64_appstream
389-ds-base-legacy-tools-1.4.3.39-3.module+el8.10.0+90328+4f014c15.aarch64.rpm352d41b80f95857e5bd60f9a75130435-ol8_aarch64_appstream
389-ds-base-libs-1.4.3.39-3.module+el8.10.0+90328+4f014c15.aarch64.rpma3b2ca6a952ce6a5019cb81229875f7a-ol8_aarch64_appstream
389-ds-base-snmp-1.4.3.39-3.module+el8.10.0+90328+4f014c15.aarch64.rpm44a7967a6a32ec462cb0cb23103ff7cb-ol8_aarch64_appstream
python3-lib389-1.4.3.39-3.module+el8.10.0+90328+4f014c15.noarch.rpm1398d7006fc3f68328e5abcd6c2aeb89-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) 389-ds-base-1.4.3.39-3.module+el8.10.0+90328+4f014c15.src.rpmd2355eee36cc4012f1482d01d67f64ac-ol8_x86_64_appstream
389-ds-base-1.4.3.39-3.module+el8.10.0+90328+4f014c15.x86_64.rpmc7ac29aee5f1df8a175bd0ae6979d60f-ol8_x86_64_appstream
389-ds-base-devel-1.4.3.39-3.module+el8.10.0+90328+4f014c15.x86_64.rpm9513f7100d6dc70aa5bf81f167146ba9-ol8_x86_64_appstream
389-ds-base-legacy-tools-1.4.3.39-3.module+el8.10.0+90328+4f014c15.x86_64.rpmc906971566032e69c6353702c52e9a4a-ol8_x86_64_appstream
389-ds-base-libs-1.4.3.39-3.module+el8.10.0+90328+4f014c15.x86_64.rpma1bf8aa3d959a7a123e522ad3f1b9bb5-ol8_x86_64_appstream
389-ds-base-snmp-1.4.3.39-3.module+el8.10.0+90328+4f014c15.x86_64.rpm039a478dd417b24a37fedd814639b1b9-ol8_x86_64_appstream
python3-lib389-1.4.3.39-3.module+el8.10.0+90328+4f014c15.noarch.rpm1398d7006fc3f68328e5abcd6c2aeb89-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete