it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4884-1] ldb security update
- Date: Fri, 02 Apr 2021 07:54:04 +0000
- Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1lSEd2-0006Ok-7i AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=/sWtzBthHQfRTXmjISxi/yf10ou8oV/mEDt6+oswvVY=; b=sL 0luNd4MOyMYeVeSzT8r3AOFIM28PPIw0GaKtBx3lI+hnMWml1R9YOLUtly7dg1v+Ff7yhtvR+5s3D mz9c9PuHu4wSUHz8FD7NeqG7bFBVNd5DlDIuSzM6Z9Bn9wNrblyZ84TiHQzmX72wQDQtR1dtmCxEc 6eIs1oZWeAYn7UcVkJiCVFwSfdRr5ZR+Q29wir8rXbeWtst4zN9RHBFQ7fs0QzdQlEs8nKDoFohvO zuvikeoNtwJSb0qBcdh8RduJ8xXWLzQll87DkJ+7GAeB/Us1fZaIn/9wRhNganc+Bu+DEhzD6SYhA 2CTi+SwqC6hVuhhD4HLq2mUlE77CCkHA==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Fri, 2 Apr 2021 07:54:21 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <5Kq1TUbVZTO.A.Hx.t2sZgB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4884-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
April 02, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : ldb
CVE ID : CVE-2020-10730 CVE-2020-27840 CVE-2021-20277
Debian Bug : 985935 985936
Multiple vulnerabilities have been discovered in ldb, a LDAP-like
embedded database built on top of TDB.
CVE-2020-10730
Andrew Bartlett discovered a NULL pointer dereference and
use-after-free flaw when handling 'ASQ' and 'VLV' LDAP controls and
combinations with the LDAP paged_results feature.
CVE-2020-27840
Douglas Bagnall discovered a heap corruption flaw via crafted
DN strings.
CVE-2021-20277
Douglas Bagnall discovered an out-of-bounds read vulnerability in
handling LDAP attributes that contains multiple consecutive
leading spaces.
For the stable distribution (buster), these problems have been fixed in
version 2:1.5.1+really1.4.6-3+deb10u1.
We recommend that you upgrade your ldb packages.
For the detailed security status of ldb please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/ldb
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmBmzXpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0S5iw//fSn7boJeXX4F8N/K+vz9UQtDSYeCTX2TLv0fI9yTyOIoIAtkTAezgoVl
P6bdIkVGSHa9SRMMfLYNEqBkBG5HgiGiOxgo0ypBynDXZTnPBa3pfmRDQ8Bcmb0e
33khq9DmE3eXaF8NuwJ+lT9H1jpni0AF4bMdwdPWIxypfHVvuW4C+1uFoz5OM17u
3Yq5nm0vUg0BDHn3OW8hPqnZEpEWdK9cOpxORnPTKG4Hn3mDVoBEdW0aCMAk+w7w
aHFWZl2cC3+2LfmwjI+moUxo0KWe5PRmUp6R2GaA2XDJbwTKTSreJvHcT1ykgs9L
rQbOMiP0hJsfUAi6R8zUvyiLLfm5JUrOlMDN7U8IpsjUb5GGkxDIZIO4CIf7Xr8a
jV7ouK9MV8G440O+pyusiqUsUmwAFWYj01SdHh0uC+lw/TtqvuvW6+DmBaXll6Ef
Ao+sh3E9LDbvGxgFqVD9/4ksRsUIbuLpdsyqoHoQWvYO1gzRTE1LrF94hs5ZATTe
PAWF0/JJKbVPDs3FeGJWnYmgNNOz0daAStbY4TGFC1oznD/SJAj5PjPCiW2QvVwf
trRZNT4rUe5VeyfFGFHoIReG70y1z1L3E/OSyVffN/4/+t36g3mxOFyghUuuIjN6
eJtE41TrTuwPXjl4pzpp7B7YIYExTg65lkxeFnN+2nMkYA8pbhE=
=arHu
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4884-1] ldb security update, Salvatore Bonaccorso, 02.04.2021
Archiv bereitgestellt durch MHonArc 2.6.24.