--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-2055
2015-02-14 23:26:22
--------------------------------------------------------------------------------

Name        : openldap
Product     : Fedora 21
Version     : 2.4.40
Release     : 3.fc21
URL         : https://www.openldap.org/
Summary     : LDAP support libraries
Description :
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools. LDAP is a set of
protocols for accessing directory services (usually phone book style
information, but other information is possible) over the Internet,
similar to the way DNS (Domain Name System) information is propagated
over the Internet. The openldap package contains configuration files,
libraries, and documentation for OpenLDAP.

--------------------------------------------------------------------------------
Update Information:

CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb 10 2015 Jan Synáček  - 2.4.40-3
- CVE-2015-1545: slapd crashes on search with deref control (#1190645)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1190643 - CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list
        https://bugzilla.redhat.com/show_bug.cgi?id=1190643
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update openldap' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/

Fedora 21: openldap Security Update

April 13, 2015
CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list

Summary

OpenLDAP is an open source suite of LDAP (Lightweight Directory Access

Protocol) applications and development tools. LDAP is a set of

protocols for accessing directory services (usually phone book style

information, but other information is possible) over the Internet,

similar to the way DNS (Domain Name System) information is propagated

over the Internet. The openldap package contains configuration files,

libraries, and documentation for OpenLDAP.

Update Information:

CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list

Change Log

* Tue Feb 10 2015 Jan Synáček - 2.4.40-3 - CVE-2015-1545: slapd crashes on search with deref control (#1190645)

References

[ 1 ] Bug #1190643 - CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list https://bugzilla.redhat.com/show_bug.cgi?id=1190643

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update openldap' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : openldap
Product : Fedora 21
Version : 2.4.40
Release : 3.fc21
URL : https://www.openldap.org/
Summary : LDAP support libraries

Related News