Oracle Linux Security Advisory ELSA-2024-4235

http://linux.oracle.com/errata/ELSA-2024-4235.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm
389-ds-base-devel-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm
389-ds-base-legacy-tools-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm
389-ds-base-libs-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm
389-ds-base-snmp-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm
python3-lib389-1.4.3.39-7.module+el8.10.0+90358+1275b17f.noarch.rpm

aarch64:
389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm
389-ds-base-devel-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm
389-ds-base-legacy-tools-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm
389-ds-base-libs-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm
389-ds-base-snmp-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm
python3-lib389-1.4.3.39-7.module+el8.10.0+90358+1275b17f.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.src.rpm

Related CVEs:

CVE-2024-2199
CVE-2024-3657




Description of changes:

[1.4.3.39-7]
- Bump version to 1.4.3.39-7
- Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z]

[1.4.3.39-6]
- Bump version to 1.4.3.39-6
- Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z]

[1.4.3.39-5]
- Bump version to 1.4.3.39-5
- Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z]

[1.4.3.39-4]
- Bump version to 1.4.3.39-4
- Resolves: RHEL-34818 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
- Resolves: RHEL-34824 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-4235: 389-ds security Important Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[1.4.3.39-7] - Bump version to 1.4.3.39-7 - Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z] [1.4.3.39-6] - Bump version to 1.4.3.39-6 - Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z] [1.4.3.39-5] - Bump version to 1.4.3.39-5 - Resolves: RHEL-16277 - LDAP connections are closed with code T2 before the IO block timeout is reached. [rhel-8.10.0.z] [1.4.3.39-4] - Bump version to 1.4.3.39-4 - Resolves: RHEL-34818 - redhat-ds:11/389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c - Resolves: RHEL-34824 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.src.rpm

x86_64

389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm 389-ds-base-devel-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm 389-ds-base-libs-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm 389-ds-base-snmp-1.4.3.39-7.module+el8.10.0+90358+1275b17f.x86_64.rpm python3-lib389-1.4.3.39-7.module+el8.10.0+90358+1275b17f.noarch.rpm

aarch64

389-ds-base-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm 389-ds-base-devel-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm 389-ds-base-legacy-tools-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm 389-ds-base-libs-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm 389-ds-base-snmp-1.4.3.39-7.module+el8.10.0+90358+1275b17f.aarch64.rpm python3-lib389-1.4.3.39-7.module+el8.10.0+90358+1275b17f.noarch.rpm

i386

Severity
Related CVEs: CVE-2024-2199 CVE-2024-3657

Related News