389-ds-base.git
3 years agoIssue 5242- Craft message may crash the server (#5243)
tbordaz [Wed, 30 Mar 2022 16:07:23 +0000 (18:07 +0200)]
Issue 5242- Craft message may crash the server (#5243)

Bug description:
A craft request can result in DoS

Fix description:
If the server fails to decode the ber value
then return an Error

relates: 5242

Reviewed by: Pierre Rogier, Mark Reynolds (thanks !)

Platforms tested:  F34

Gbp-Pq: Name 0001-Issue-5242-Craft-message-may-crash-the-server-5243.patch

3 years ago[PATCH] Revert "Issue 3584 - Fix PBKDF2_SHA256 hashing in FIPS mode (#4949)"
Timo Aaltonen [Wed, 15 Dec 2021 19:40:38 +0000 (21:40 +0200)]
[PATCH] Revert "Issue 3584 - Fix PBKDF2_SHA256 hashing in FIPS mode (#4949)"

This reverts commit b0d06615e1117799ec156d51489cd49c92635cca.

Gbp-Pq: Name 0001-Revert-Issue-3584-Fix-PBKDF2_SHA256-hashing-in-FIPS-.patch

3 years agofix-saslpath
Debian FreeIPA Team [Tue, 13 Sep 2022 19:10:45 +0000 (20:10 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

3 years ago389-ds-base (2.0.15-1.1) unstable; urgency=medium
Adrian Bunk [Tue, 13 Sep 2022 19:10:45 +0000 (20:10 +0100)]
389-ds-base (2.0.15-1.1) unstable; urgency=medium

  * Non-maintainer upload.
  * CVE-2022-0918: unauthenticated attacker with network access to
    the LDAP port could cause a denial of service (Closes: #1016445)

[dgit import unpatched 389-ds-base 2.0.15-1.1]

3 years agoImport 389-ds-base_2.0.15-1.1.debian.tar.xz
Adrian Bunk [Tue, 13 Sep 2022 19:10:45 +0000 (20:10 +0100)]
Import 389-ds-base_2.0.15-1.1.debian.tar.xz

[dgit import tarball 389-ds-base 2.0.15-1.1 389-ds-base_2.0.15-1.1.debian.tar.xz]

3 years agoImport 389-ds-base_2.0.15.orig.tar.gz
Timo Aaltonen [Wed, 13 Apr 2022 11:11:20 +0000 (12:11 +0100)]
Import 389-ds-base_2.0.15.orig.tar.gz

[dgit import orig 389-ds-base_2.0.15.orig.tar.gz]