Bugzilla – Bug 997256
VUL-0: CVE-2016-4992: 389-ds: Information disclosure via repeated use of LDAP ADD operation
Last modified: 2018-01-09 13:50:32 UTC
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-5-13.html Detailed Changelog since 1.3.5.4 CVE-2016-4992 389-ds-base: Information disclosure via repeated use of LDAP ADD operation, etc. References: https://bugzilla.redhat.com/show_bug.cgi?id=1347760 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4992 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4992.html
note there is also a mention of tmp file bugs metioned in the change log at http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-5-13.html
bugbot adjusting priority
master: https://pagure.io/389-ds-base/c/b8767d510d11c7cbfede24daaae3348b9f028f47 https://pagure.io/389-ds-base/c/caa351ae0cc81cbf2309a43c5f74b359cda152d0 https://pagure.io/389-ds-base/c/8bfe4bbf3d61d4eaf4abac6515c95b38ac39b195 1.3.4.x branch: https://pagure.io/389-ds-base/c/e88a1ba32ec1b02f278e7febef6024f4e6bf9f55 https://pagure.io/389-ds-base/c/c5521864b2996db2ae18f24ef34acb6aec92ad78 https://pagure.io/389-ds-base/c/b338616f66d4d51536b94edd9ae7f0dd10fbebd0 https://pagure.io/389-ds-base/c/bd0bf95baa1c2807e144efbd30bad45237fd53e1 Can you roll an update?
Howard, could I bother you for a maintenance update for Leap for these bugs? 991201,997256,1007004,1020670,1051997,1069067,1069074
This is an autogenerated message for OBS integration: This bug (997256) was mentioned in https://build.opensuse.org/request/show/548604 42.2 / 389-ds
This is an autogenerated message for OBS integration: This bug (997256) was mentioned in https://build.opensuse.org/request/show/554810 42.2 / 389-ds
releasing, done. Thanks Howard
openSUSE-SU-2017:3362-1: An update that solves four vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1007004,1020670,1051997,1069067,1069074,997256 CVE References: CVE-2016-4992,CVE-2016-5405,CVE-2017-2668,CVE-2017-7551 Sources used: openSUSE Leap 42.3 (src): 389-ds-1.3.4.5-8.1 openSUSE Leap 42.2 (src): 389-ds-1.3.4.5-5.5.1
All updates released.