Release Info

Advisory: CLSA-2023:1688678407

OS: Ubuntu 18.04 ELS

Public date: 2023-07-06 17:20:09

Project: openldap

Version: 2.4.45+dfsg-1ubuntu1.11+tuxcare.els1

Errata link: https://errata.cloudlinux.com/ubuntu18-els/CLSA-2023-1688678407.html

Changelog

* SECURITY UPDATE: null pointer dereference in ber_memalloc_x() - debian/patches/CVE-2023-2953.patch: added check for strdup failure in ldif_open_url, ldap_url_parsehosts. - CVE-2023-2953

Update

Update command: apt-get update apt-get --only-upgrade install openldap*

Packages list

ldap-utils_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb libldap-2.4-2_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb libldap-common_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_all.deb libldap2-dev_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb slapd_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb slapd-smbk5pwd_2.4.45+dfsg-1ubuntu1.11+tuxcare.els1_amd64.deb

CVEs

CVE-2023-2953