[CLSA-2023:1689700365] Fix CVE(s): CVE-2023-2953
Type:
security
Severity:
Important
Release date:
2023-07-18 17:12:50 UTC
Description:
* SECURITY UPDATE: null pointer dereference in ber_memalloc_x() - debian/patches/CVE-2023-2953.patch: added check for strdup failure in ldif_open_url, ldap_url_parsehosts. - CVE-2023-2953
Updated packages:
  • ldap-utils_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb
    sha:52aa728283e9c2abe778e1081c1c108cb25562b7
  • libldap-2.4-2_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb
    sha:617a495c071e06479b34e4dd71d66509bc25b49f
  • libldap2-dev_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb
    sha:3d9f226338ab0945685352444413a6311c7f709e
  • slapd_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb
    sha:2a4a05e76548990050f90485d3c94c789d0d2831
  • slapd-smbk5pwd_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb
    sha:f15c7efa0c4de07090362b238d9a64f1b152f878
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.