Files
buildroot/package
Fabrice Fontaine 3b72c7f8d9 package/openldap: security bump to version 2.4.57
Fixes the following security issues:

- CVE-2020-36221: An integer underflow was discovered in OpenLDAP before
  2.4.57 leading to slapd crashes in the Certificate Exact Assertion
  processing, resulting in denial of service (schema_init.c
  serialNumberAndIssuerCheck).

- CVE-2020-36222: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  an assertion failure in slapd in the saslAuthzTo validation, resulting in
  denial of service.

- CVE-2020-36223: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  a slapd crash in the Values Return Filter control handling, resulting in
  denial of service (double free and out-of-bounds read).

- CVE-2020-36224: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  an invalid pointer free and slapd crash in the saslAuthzTo processing,
  resulting in denial of service.

- CVE-2020-36225: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  a double free and slapd crash in the saslAuthzTo processing, resulting in
  denial of service.

- CVE-2020-36226: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  a memch->bv_len miscalculation and slapd crash in the saslAuthzTo
  processing, resulting in denial of service.

- CVE-2020-36227: A flaw was discovered in OpenLDAP before 2.4.57 leading to
  an infinite loop in slapd with the cancel_extop Cancel operation,
  resulting in denial of service.

- CVE-2020-36228: An integer underflow was discovered in OpenLDAP before
  2.4.57 leading to a slapd crash in the Certificate List Exact Assertion
  processing, resulting in denial of service.

- CVE-2020-36229: A flaw was discovered in ldap_X509dn2bv in OpenLDAP before
  2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring,
  resulting in denial of service.

- CVE-2020-36230: A flaw was discovered in OpenLDAP before 2.4.57 leading in
  an assertion failure in slapd in the X.509 DN parsing in decode.c
  ber_next_element, resulting in denial of service.

https://www.openldap.org/software/release/changes.html

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 46c4c9684d)
[Peter: mark as security bump, add CVE info]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2021-01-28 19:34:13 +01:00
..
2020-09-14 22:16:23 +02:00
2020-09-30 22:56:40 +02:00
2020-10-06 21:05:07 +02:00
2020-11-29 22:15:42 +01:00
2020-11-18 10:48:11 +01:00
2020-09-02 18:14:46 +02:00
2020-09-22 21:41:06 +02:00
2020-10-13 13:23:33 +02:00
2020-11-09 11:00:11 +01:00
2020-09-01 09:18:37 +02:00
2020-11-26 17:10:02 +01:00
2020-10-04 11:38:01 +02:00
2020-09-09 22:54:26 +02:00
2020-10-31 22:22:28 +01:00
2020-11-12 21:53:32 +01:00
2020-11-09 17:01:30 +01:00
2020-11-04 20:34:48 +01:00
2020-11-01 10:03:36 +01:00
2020-09-17 21:40:39 +02:00
2020-11-01 10:03:36 +01:00
2020-10-12 08:33:42 +02:00
2020-09-21 22:37:31 +02:00
2020-11-03 23:16:48 +01:00
2020-10-15 23:36:40 +02:00
2020-09-20 16:08:09 +02:00
2020-09-07 23:15:11 +02:00
2020-09-08 22:31:51 +02:00
2020-11-07 13:21:15 +01:00
2020-11-29 22:21:37 +01:00
2020-12-01 23:01:27 +01:00
2020-11-10 08:29:37 +01:00
2020-10-25 15:52:40 +01:00
2020-09-19 21:10:27 +02:00
2020-10-31 23:44:06 +01:00
2020-10-04 20:45:35 +02:00
2020-12-13 00:54:16 +01:00
2020-10-31 23:01:00 +01:00
2020-11-07 14:19:01 +01:00
2020-09-19 21:18:26 +02:00
2020-09-05 23:30:10 +02:00
2020-10-18 13:28:37 +02:00
2020-11-22 15:26:49 +01:00
2020-09-07 21:35:21 +02:00
2020-09-20 15:36:47 +02:00
2020-10-04 21:53:43 +02:00
2020-10-24 22:58:03 +02:00
2020-08-29 23:13:51 +02:00
2020-09-19 14:52:33 +02:00
2020-09-03 20:51:04 +02:00
2020-11-16 21:29:58 +01:00
2020-09-19 14:22:00 +02:00
2020-09-19 22:08:37 +02:00
2020-10-31 21:42:38 +01:00
2020-11-03 20:55:04 +01:00
2020-10-27 10:25:41 +01:00
2020-10-06 21:04:37 +02:00
2020-08-31 22:18:09 +02:00
2020-10-15 00:09:48 +02:00
2020-09-22 21:59:02 +02:00
2020-10-13 13:33:33 +02:00
2020-10-04 11:38:01 +02:00
2020-11-22 15:31:36 +01:00
2021-01-28 18:23:43 +01:00
2021-01-05 22:52:08 +01:00
2020-10-12 22:30:09 +02:00
2020-10-04 11:38:01 +02:00
2020-09-20 15:05:59 +02:00
2021-01-28 18:00:46 +01:00
2020-10-29 23:26:21 +01:00
2020-11-12 21:55:11 +01:00
2020-12-12 12:02:27 +01:00
2020-09-19 23:22:59 +02:00
2021-01-12 18:25:27 +01:00
2020-09-20 15:06:00 +02:00
2020-11-01 10:03:36 +01:00
2020-11-01 10:03:36 +01:00
2021-01-19 15:55:42 +01:00