openldap (2.4.47+dfsg-3+deb10u5) buster-security; urgency=high
authorRyan Tandy <ryan@nardis.ca>
Fri, 22 Jan 2021 03:54:40 +0000 (03:54 +0000)
committerRyan Tandy <ryan@nardis.ca>
Fri, 22 Jan 2021 03:54:40 +0000 (03:54 +0000)
commitacdc3fe48786a01e38e844eacb13ea9806d3f2cf
treefc4eaceea93fd130a8f63489d561c7214dfc3bbf
parenta1459c6cf9555642855ce6cf657ad07e24b886c9
parentf685f252c8fe1405441d759cbad16d7dc166766e
openldap (2.4.47+dfsg-3+deb10u5) buster-security; urgency=high

  * Fix slapd crashes in Certificate Exact Assertion processing
    (ITS#9404, ITS#9424) (CVE-2020-36221)
  * Fix slapd assertion failures in saslAuthzTo validation
    (ITS#9406, ITS#9407) (CVE-2020-36222)
  * Fix slapd crash in Values Return Filter control handling
    (ITS#9408) (CVE-2020-36223)
  * Fix slapd crashes in saslAuthzTo processing (ITS#9409, ITS#9412, ITS#9413)
    (CVE-2020-36224, CVE-2020-36225, CVE-2020-36226)
  * Fix slapd assertion failure in X.509 DN parsing
    (ITS#9423) (CVE-2020-36230)
  * Fix slapd crash in X.509 DN parsing (ITS#9425) (CVE-2020-36229)
  * Fix slapd crash in Certificate List Exact Assertion processing
    (ITS#9427) (CVE-2020-36228)
  * Fix slapd infinite loop with Cancel operation (ITS#9428) (CVE-2020-36227)

[dgit import unpatched openldap 2.4.47+dfsg-3+deb10u5]
143 files changed:
debian/DB_CONFIG
debian/README.DB_CONFIG
debian/TODO
debian/USE-CASES
debian/changelog
debian/clean
debian/compat
debian/configure.options
debian/control
debian/copyright
debian/dh_installscripts-common
debian/ldap-utils.README.Debian
debian/ldap-utils.dirs
debian/ldap-utils.install
debian/ldap-utils.manpages
debian/ldiftopasswd
debian/libldap-2.4-2.README.Debian
debian/libldap-2.4-2.install
debian/libldap-2.4-2.links.in
debian/libldap-2.4-2.lintian-overrides
debian/libldap-2.4-2.shlibs
debian/libldap-2.4-2.symbols
debian/libldap-common.install
debian/libldap-common.manpages
debian/libldap2-dev.dirs
debian/libldap2-dev.install
debian/libldap2-dev.links.in
debian/libldap2-dev.manpages
debian/patches/ITS-8964-Do-not-free-original-filter.patch
debian/patches/ITS-9038-Another-test028-typo.patch
debian/patches/ITS-9038-Fix-typo-in-test-script.patch
debian/patches/ITS-9038-Update-test028-to-test-this-is-enforced.patch
debian/patches/ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch
debian/patches/ITS-9052-zero-out-sasl_ssf-in-connection_init.patch
debian/patches/ITS-9202-limit-depth-of-nested-filters.patch
debian/patches/ITS-9370-check-for-equality-rule-on-old_rdn.patch
debian/patches/ITS-9383-remove-assert-in-certificateListValidate.patch
debian/patches/ITS-9384-remove-assert-in-obsolete-csnNormalize23.patch
debian/patches/ITS-9404-fix-serialNumberAndIssuerCheck.patch
debian/patches/ITS-9406-9407-remove-saslauthz-asserts.patch
debian/patches/ITS-9406-fix-debug-msg.patch
debian/patches/ITS-9408-fix-vrfilter-double-free.patch
debian/patches/ITS-9409-saslauthz-use-ch_free-on-normalized-DN.patch
debian/patches/ITS-9409-saslauthz-use-slap_sl_free-in-prev-commit.patch
debian/patches/ITS-9411-fix-thisUpdate-check.patch
debian/patches/ITS-9412-fix-AVA_Sort-on-invalid-RDN.patch
debian/patches/ITS-9413-fix-slap_parse_user.patch
debian/patches/ITS-9423-ldap_X509dn2bv-check-for-invalid-BER-after-.patch
debian/patches/ITS-9424-fix-serialNumberAndIssuerSerialCheck.patch
debian/patches/ITS-9425-add-more-checks-to-ldap_X509dn2bv.patch
debian/patches/ITS-9427-fix-issuerAndThisUpdateCheck.patch
debian/patches/ITS-9428-fix-cancel-exop.patch
debian/patches/ITS6035-olcauthzregex-needs-restart.patch
debian/patches/add-tlscacert-option-to-ldap-conf
debian/patches/contrib-makefiles
debian/patches/do-not-second-guess-sonames
debian/patches/evolution-ntlm
debian/patches/fix-build-top-mk
debian/patches/getaddrinfo-is-threadsafe
debian/patches/index-files-created-as-root
debian/patches/lastbind-makefile-manpage
debian/patches/ldap-conf-tls-cacertdir
debian/patches/ldapi-socket-place
debian/patches/libldap-symbol-versions
debian/patches/man-slapd
debian/patches/no-AM_INIT_AUTOMAKE
debian/patches/no-bdb-ABI-second-guessing
debian/patches/no-gnutls_global_set_mutex
debian/patches/sasl-default-path
debian/patches/series
debian/patches/set-maintainer-name
debian/patches/slapi-errorlog-file
debian/patches/smbk5pwd-makefile-manpage
debian/patches/switch-to-lt_dlopenadvise-to-get-RTLD_GLOBAL-set.diff
debian/patches/wrong-database-location
debian/po/POTFILES.in
debian/po/ca.po
debian/po/cs.po
debian/po/da.po
debian/po/de.po
debian/po/es.po
debian/po/eu.po
debian/po/fi.po
debian/po/fr.po
debian/po/gl.po
debian/po/it.po
debian/po/ja.po
debian/po/nl.po
debian/po/pt.po
debian/po/pt_BR.po
debian/po/ru.po
debian/po/sk.po
debian/po/sv.po
debian/po/templates.pot
debian/po/tr.po
debian/po/vi.po
debian/rules
debian/schema/README
debian/schema/collective.schema
debian/schema/compare-schema
debian/schema/corba.schema
debian/schema/core.ldif
debian/schema/core.schema
debian/schema/cosine.schema
debian/schema/duaconf.schema
debian/schema/inetorgperson.schema
debian/schema/java.schema
debian/schema/pmi.schema
debian/schema/ppolicy.schema
debian/slapd-contrib.examples
debian/slapd-contrib.install
debian/slapd-contrib.lintian-overrides
debian/slapd-contrib.manpages
debian/slapd.NEWS
debian/slapd.README.Debian
debian/slapd.backup
debian/slapd.conf
debian/slapd.config
debian/slapd.default
debian/slapd.dirs
debian/slapd.docs
debian/slapd.examples
debian/slapd.init
debian/slapd.init.ldif
debian/slapd.install
debian/slapd.links
debian/slapd.lintian-overrides
debian/slapd.manpages
debian/slapd.postinst
debian/slapd.postrm
debian/slapd.preinst
debian/slapd.prerm
debian/slapd.scripts-common
debian/slapd.templates
debian/slapi-dev.install
debian/slapo-pw-pbkdf2.5
debian/source.lintian-overrides
debian/source/format
debian/tests/check_upgradepath
debian/tests/create_account
debian/tests/find_unused_functions
debian/tests/hammer_slapd
debian/watch