Release Info

Advisory: CLSA-2023:1689700365

OS: Ubuntu 16.04 ELS

Public date: 2023-07-18 13:12:47

Project: openldap

Version: 2.4.42+dfsg-2ubuntu3.13.tuxcare.els2

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2023-1689700365.html

Changelog

* SECURITY UPDATE: null pointer dereference in ber_memalloc_x() - debian/patches/CVE-2023-2953.patch: added check for strdup failure in ldif_open_url, ldap_url_parsehosts. - CVE-2023-2953

Update

Update command: apt-get update apt-get --only-upgrade install openldap*

Packages list

ldap-utils_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb libldap-2.4-2_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb libldap2-dev_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb slapd_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb slapd-smbk5pwd_2.4.42+dfsg-2ubuntu3.13.tuxcare.els2_amd64.deb

CVEs

CVE-2023-2953