openldap (2.4.47+dfsg-3+deb10u4) buster-security; urgency=high
authorRyan Tandy <ryan@nardis.ca>
Tue, 17 Nov 2020 01:23:45 +0000 (01:23 +0000)
committerRyan Tandy <ryan@nardis.ca>
Tue, 17 Nov 2020 01:23:45 +0000 (01:23 +0000)
commit03f8fc0a20bc35758136ef373c097be82b0b08d7
tree0c9275fb3ef79387aeda2ec54a3ba2eca4ad64e5
parenta1459c6cf9555642855ce6cf657ad07e24b886c9
parent308d3cf5499bd30802ad6e44c73e4b6a3cfe77fc
openldap (2.4.47+dfsg-3+deb10u4) buster-security; urgency=high

  * Fix slapd abort due to assertion failure in Certificate List syntax
    validation (ITS#9383) (CVE-2020-25709)
  * Fix slapd abort due to assertion failure in CSN normalization with invalid
    input (ITS#9384) (CVE-2020-25710)

[dgit import unpatched openldap 2.4.47+dfsg-3+deb10u4]
129 files changed:
debian/DB_CONFIG
debian/README.DB_CONFIG
debian/TODO
debian/USE-CASES
debian/changelog
debian/clean
debian/compat
debian/configure.options
debian/control
debian/copyright
debian/dh_installscripts-common
debian/ldap-utils.README.Debian
debian/ldap-utils.dirs
debian/ldap-utils.install
debian/ldap-utils.manpages
debian/ldiftopasswd
debian/libldap-2.4-2.README.Debian
debian/libldap-2.4-2.install
debian/libldap-2.4-2.links.in
debian/libldap-2.4-2.lintian-overrides
debian/libldap-2.4-2.shlibs
debian/libldap-2.4-2.symbols
debian/libldap-common.install
debian/libldap-common.manpages
debian/libldap2-dev.dirs
debian/libldap2-dev.install
debian/libldap2-dev.links.in
debian/libldap2-dev.manpages
debian/patches/ITS-8964-Do-not-free-original-filter.patch
debian/patches/ITS-9038-Another-test028-typo.patch
debian/patches/ITS-9038-Fix-typo-in-test-script.patch
debian/patches/ITS-9038-Update-test028-to-test-this-is-enforced.patch
debian/patches/ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch
debian/patches/ITS-9052-zero-out-sasl_ssf-in-connection_init.patch
debian/patches/ITS-9202-limit-depth-of-nested-filters.patch
debian/patches/ITS-9370-check-for-equality-rule-on-old_rdn.patch
debian/patches/ITS-9383-remove-assert-in-certificateListValidate.patch
debian/patches/ITS-9384-remove-assert-in-obsolete-csnNormalize23.patch
debian/patches/ITS6035-olcauthzregex-needs-restart.patch
debian/patches/add-tlscacert-option-to-ldap-conf
debian/patches/contrib-makefiles
debian/patches/do-not-second-guess-sonames
debian/patches/evolution-ntlm
debian/patches/fix-build-top-mk
debian/patches/getaddrinfo-is-threadsafe
debian/patches/index-files-created-as-root
debian/patches/lastbind-makefile-manpage
debian/patches/ldap-conf-tls-cacertdir
debian/patches/ldapi-socket-place
debian/patches/libldap-symbol-versions
debian/patches/man-slapd
debian/patches/no-AM_INIT_AUTOMAKE
debian/patches/no-bdb-ABI-second-guessing
debian/patches/no-gnutls_global_set_mutex
debian/patches/sasl-default-path
debian/patches/series
debian/patches/set-maintainer-name
debian/patches/slapi-errorlog-file
debian/patches/smbk5pwd-makefile-manpage
debian/patches/switch-to-lt_dlopenadvise-to-get-RTLD_GLOBAL-set.diff
debian/patches/wrong-database-location
debian/po/POTFILES.in
debian/po/ca.po
debian/po/cs.po
debian/po/da.po
debian/po/de.po
debian/po/es.po
debian/po/eu.po
debian/po/fi.po
debian/po/fr.po
debian/po/gl.po
debian/po/it.po
debian/po/ja.po
debian/po/nl.po
debian/po/pt.po
debian/po/pt_BR.po
debian/po/ru.po
debian/po/sk.po
debian/po/sv.po
debian/po/templates.pot
debian/po/tr.po
debian/po/vi.po
debian/rules
debian/schema/README
debian/schema/collective.schema
debian/schema/compare-schema
debian/schema/corba.schema
debian/schema/core.ldif
debian/schema/core.schema
debian/schema/cosine.schema
debian/schema/duaconf.schema
debian/schema/inetorgperson.schema
debian/schema/java.schema
debian/schema/pmi.schema
debian/schema/ppolicy.schema
debian/slapd-contrib.examples
debian/slapd-contrib.install
debian/slapd-contrib.lintian-overrides
debian/slapd-contrib.manpages
debian/slapd.NEWS
debian/slapd.README.Debian
debian/slapd.backup
debian/slapd.conf
debian/slapd.config
debian/slapd.default
debian/slapd.dirs
debian/slapd.docs
debian/slapd.examples
debian/slapd.init
debian/slapd.init.ldif
debian/slapd.install
debian/slapd.links
debian/slapd.lintian-overrides
debian/slapd.manpages
debian/slapd.postinst
debian/slapd.postrm
debian/slapd.preinst
debian/slapd.prerm
debian/slapd.scripts-common
debian/slapd.templates
debian/slapi-dev.install
debian/slapo-pw-pbkdf2.5
debian/source.lintian-overrides
debian/source/format
debian/tests/check_upgradepath
debian/tests/create_account
debian/tests/find_unused_functions
debian/tests/hammer_slapd
debian/watch