[CLSA-2023:1688678407] Fix CVE(s): CVE-2023-2953
Type:
security
Severity:
Important
Release date:
2023-07-06 21:20:13 UTC
Description:
* SECURITY UPDATE: null pointer dereference in ber_memalloc_x() - debian/patches/CVE-2023-2953.patch: added check for strdup failure in ldif_open_url, ldap_url_parsehosts. - CVE-2023-2953
Updated packages:
  • ldap-utils_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb
    sha:7f8ba08f4053a64b863e80e55f74299612c155c1
  • libldap-2.4-2_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb
    sha:ba90e8f5c175ef81dae9c04c81a15941355969fc
  • libldap-common_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_all.deb
    sha:e390fb4c6ec57894324f662664fc59f005d60115
  • libldap2-dev_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb
    sha:6f9cdeba9328b2a1019cb2df4e35d40ed8e64235
  • slapd_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb
    sha:276b407fe58e0a7dac9c09588244defd7aa710b6
  • slapd-smbk5pwd_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb
    sha:0e21a207b611da3be34e8936d652f25d15c62362
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.