~ubuntu-branches/ubuntu/hardy/openldap2.3/hardy-security

« back to all changes in this revision

Viewing changes to debian/patches/series

  • Committer: Bazaar Package Importer
  • Author(s): Emanuele Gentili
  • Date: 2008-03-02 16:34:30 UTC
  • Revision ID: james.westby@ubuntu.com-20080302163430-p9d4efck79ee3s1v
Tags: 2.4.7-5ubuntu2
* SECURITY UPDATE: 
 + debian/patches/SECURITY_CVE-2008-0658.patch (LP: #197077)
   slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 
   allows remote authenticated users to cause a denial of service (daemon crash) 
   via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related 
   issue to CVE-2007-6698.

* References
 - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0658
 - http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358

Show diffs side-by-side

added added

removed removed

Lines of Context:
12
12
entryCSN-backwards-compatibility
13
13
slapd-tlsverifyclient-default -p0
14
14
gnutls-altname-nulterminated -p0
 
15
SECURITY_CVE-2008-0658.patch