Bug 916897 (CVE-2015-1545) - VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control and empty attr list
Summary: VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control a...
Status: RESOLVED FIXED
Alias: CVE-2015-1545
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2015-02-26
Assignee: Peter Varkoly
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113616/
Whiteboard: maint:released:sle11-sp1:61598
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-09 12:04 UTC by Johannes Segitz
Modified: 2017-06-07 10:02 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2015-02-09 23:04:41 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2015-02-12 10:45:11 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-02-26.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60662
Comment 4 Howard Guo 2015-04-09 11:02:04 UTC
A bug fix has been submitted to SP3:Update, awaiting review.
Comment 7 Swamp Workflow Management 2015-05-15 20:05:43 UTC
SUSE-SU-2015:0887-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 846389,905959,916897,916914
CVE References: CVE-2013-4449,CVE-2015-1545,CVE-2015-1546
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    openldap2-2.4.26-0.30.1, openldap2-client-2.4.26-0.30.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    openldap2-2.4.26-0.30.1, openldap2-client-2.4.26-0.30.1
SUSE Linux Enterprise Server 11 SP3 (src):    openldap2-2.4.26-0.30.1, openldap2-client-2.4.26-0.30.1
SUSE Linux Enterprise Security Module 11 SP3 (src):    openldap2-client-openssl1-2.4.26-0.30.2
SUSE Linux Enterprise Desktop 11 SP3 (src):    openldap2-client-2.4.26-0.30.1
Comment 8 Swamp Workflow Management 2015-06-18 07:05:31 UTC
SUSE-SU-2015:1077-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 905959,916897,916914
CVE References: CVE-2015-1545,CVE-2015-1546
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    openldap2-2.4.39-15.1, openldap2-2.4.39-16.1, openldap2-client-2.4.39-15.1, openldap2-client-2.4.39-16.1
SUSE Linux Enterprise Server 12 (src):    openldap2-2.4.39-15.1, openldap2-2.4.39-16.1, openldap2-client-2.4.39-15.1, openldap2-client-2.4.39-16.1
SUSE Linux Enterprise Module for Legacy Software 12 (src):    openldap2-2.4.39-15.1, openldap2-2.4.39-16.1
SUSE Linux Enterprise Desktop 12 (src):    openldap2-client-2.4.39-16.1
 12 (src):    openldap2-2.4.39-16.1
Comment 9 Bernhard Wiedemann 2015-07-10 13:00:18 UTC
This is an autogenerated message for OBS integration:
This bug (916897) was mentioned in
https://build.opensuse.org/request/show/315869 13.2 / openldap2
Comment 10 Andreas Stieger 2015-07-20 12:11:34 UTC
Review open for 10 days, please review:
https://build.opensuse.org/request/show/315869
Comment 11 Andreas Stieger 2015-07-23 07:44:45 UTC
Maintenance request in review for 13 days, can you please review:
https://build.opensuse.org/request/show/315869

I believe Viktor did not submit this to the devel project. Can you please ensure the SLE patches are brought into Factory?
Comment 12 Bernhard Wiedemann 2015-07-23 09:00:29 UTC
This is an autogenerated message for OBS integration:
This bug (916897) was mentioned in
https://build.opensuse.org/request/show/318094 13.1 / openldap2
Comment 13 Swamp Workflow Management 2015-07-31 08:27:32 UTC
openSUSE-SU-2015:1325-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 905959,916897,916914
CVE References: CVE-2015-1545,CVE-2015-1546
Sources used:
openSUSE 13.2 (src):    openldap2-2.4.39-8.5.1, openldap2-client-2.4.39-8.5.1
openSUSE 13.1 (src):    openldap2-2.4.33-8.3.1, openldap2-client-2.4.33-8.3.1
Comment 14 Marcus Meissner 2015-09-01 15:55:21 UTC
done i think
Comment 18 Bernhard Wiedemann 2017-06-06 14:01:52 UTC
This is an autogenerated message for OBS integration:
This bug (916897) was mentioned in
https://build.opensuse.org/request/show/501412 Factory / openldap2
Comment 19 Bernhard Wiedemann 2017-06-07 10:02:23 UTC
This is an autogenerated message for OBS integration:
This bug (916897) was mentioned in
https://build.opensuse.org/request/show/501631 Factory / openldap2