-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: libldb security, bug fix, and enhancement update
Advisory ID:       RHSA-2020:4568-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:4568
Issue date:        2020-11-03
CVE Names:         CVE-2020-10730 
====================================================================
1. Summary:

An update for libldb is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64

3. Description:

The libldb packages provide an extensible library that implements an
LDAP-like API to access remote LDAP servers, or use local TDB databases.

The following packages have been upgraded to a later upstream version:
libldb (2.1.3). (BZ#1817567)

Security Fix(es):

* samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP
Server with ASQ, VLV and paged_results (CVE-2020-10730)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.3 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1817567 - Rebase libldb to the version required by Samba
1849489 - CVE-2020-10730 samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results

6. Package List:

Red Hat Enterprise Linux BaseOS (v. 8):

Source:
libldb-2.1.3-2.el8.src.rpm

aarch64:
ldb-tools-2.1.3-2.el8.aarch64.rpm
ldb-tools-debuginfo-2.1.3-2.el8.aarch64.rpm
libldb-2.1.3-2.el8.aarch64.rpm
libldb-debuginfo-2.1.3-2.el8.aarch64.rpm
libldb-debugsource-2.1.3-2.el8.aarch64.rpm
libldb-devel-2.1.3-2.el8.aarch64.rpm
python3-ldb-2.1.3-2.el8.aarch64.rpm
python3-ldb-debuginfo-2.1.3-2.el8.aarch64.rpm

ppc64le:
ldb-tools-2.1.3-2.el8.ppc64le.rpm
ldb-tools-debuginfo-2.1.3-2.el8.ppc64le.rpm
libldb-2.1.3-2.el8.ppc64le.rpm
libldb-debuginfo-2.1.3-2.el8.ppc64le.rpm
libldb-debugsource-2.1.3-2.el8.ppc64le.rpm
libldb-devel-2.1.3-2.el8.ppc64le.rpm
python3-ldb-2.1.3-2.el8.ppc64le.rpm
python3-ldb-debuginfo-2.1.3-2.el8.ppc64le.rpm

s390x:
ldb-tools-2.1.3-2.el8.s390x.rpm
ldb-tools-debuginfo-2.1.3-2.el8.s390x.rpm
libldb-2.1.3-2.el8.s390x.rpm
libldb-debuginfo-2.1.3-2.el8.s390x.rpm
libldb-debugsource-2.1.3-2.el8.s390x.rpm
libldb-devel-2.1.3-2.el8.s390x.rpm
python3-ldb-2.1.3-2.el8.s390x.rpm
python3-ldb-debuginfo-2.1.3-2.el8.s390x.rpm

x86_64:
ldb-tools-2.1.3-2.el8.x86_64.rpm
ldb-tools-debuginfo-2.1.3-2.el8.i686.rpm
ldb-tools-debuginfo-2.1.3-2.el8.x86_64.rpm
libldb-2.1.3-2.el8.i686.rpm
libldb-2.1.3-2.el8.x86_64.rpm
libldb-debuginfo-2.1.3-2.el8.i686.rpm
libldb-debuginfo-2.1.3-2.el8.x86_64.rpm
libldb-debugsource-2.1.3-2.el8.i686.rpm
libldb-debugsource-2.1.3-2.el8.x86_64.rpm
libldb-devel-2.1.3-2.el8.i686.rpm
libldb-devel-2.1.3-2.el8.x86_64.rpm
python3-ldb-2.1.3-2.el8.i686.rpm
python3-ldb-2.1.3-2.el8.x86_64.rpm
python3-ldb-debuginfo-2.1.3-2.el8.i686.rpm
python3-ldb-debuginfo-2.1.3-2.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-10730
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBX6I2oNzjgjWX9erEAQiLyQ/+N6gB8d/TbPssawkd/aW4idSUkUM2i01O
l+deh67GhXH0/D9nu3Vy7D/oGxWFG/pIe40iFZu0Cg5Lb/VT9hXHW2Fd/v6JbEI7
qukhQ8iS1sbq59NQS+tA78pctdPSRfNukGlw4HYz3pbVQB80qTY1HOigT3ionhyU
v0xBA/cczvq2i9tzbTc7h9k/U29kRVzac3NRWMJtGgtgnzB0TMyuJLO1P6/N1moS
7aNsqlkvG+vzzwSjVOQN4o41bpj1Wh0FAnIi3BUWu3QVLrEdUjnzTzyqeIyZGn6l
3rnerRQU6eJWmyXUvj/ZR+l3dxSiisUoK7Eg4hAIUXjlpg1ODg2su/BG6JO29Spt
WjXJZuZkwbez3Bo0OageL2nMA4hkxSFcLP0dnMaqV1Ain85q1KfakkFq4wmgPhUE
5pskIdmCjtnoa07e6VuaahAmiHu2feBCYpj3/vl3uw0K3Ps7PMVr69dC/54VZWYO
oHq+z/Bz1qmbe1fYcbnkOfnIEu21dNkxsLfPyVEE2qnRez/ru9kr0AfZ1KHM8hCN
S2ccRBA7JO5/D4CH2cA1aKsSrfpZUX3Mlk8fVW0n5RxCl1PmkttKFY8suY55Lgnl
r8Kx57t1hxkuulYnyEp4YvqfVRzrtnsyr8MqoGfcAOlgrRTHbCZUCCP/x8sXyPgy
HZpM09Wgxks=DgDC
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-4568:01 Moderate: libldb security, bug fix,

An update for libldb is now available for Red Hat Enterprise Linux 8

Summary

The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases.
The following packages have been upgraded to a later upstream version: libldb (2.1.3). (BZ#1817567)
Security Fix(es):
* samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results (CVE-2020-10730)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-10730 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/

Package List

Red Hat Enterprise Linux BaseOS (v. 8):
Source: libldb-2.1.3-2.el8.src.rpm
aarch64: ldb-tools-2.1.3-2.el8.aarch64.rpm ldb-tools-debuginfo-2.1.3-2.el8.aarch64.rpm libldb-2.1.3-2.el8.aarch64.rpm libldb-debuginfo-2.1.3-2.el8.aarch64.rpm libldb-debugsource-2.1.3-2.el8.aarch64.rpm libldb-devel-2.1.3-2.el8.aarch64.rpm python3-ldb-2.1.3-2.el8.aarch64.rpm python3-ldb-debuginfo-2.1.3-2.el8.aarch64.rpm
ppc64le: ldb-tools-2.1.3-2.el8.ppc64le.rpm ldb-tools-debuginfo-2.1.3-2.el8.ppc64le.rpm libldb-2.1.3-2.el8.ppc64le.rpm libldb-debuginfo-2.1.3-2.el8.ppc64le.rpm libldb-debugsource-2.1.3-2.el8.ppc64le.rpm libldb-devel-2.1.3-2.el8.ppc64le.rpm python3-ldb-2.1.3-2.el8.ppc64le.rpm python3-ldb-debuginfo-2.1.3-2.el8.ppc64le.rpm
s390x: ldb-tools-2.1.3-2.el8.s390x.rpm ldb-tools-debuginfo-2.1.3-2.el8.s390x.rpm libldb-2.1.3-2.el8.s390x.rpm libldb-debuginfo-2.1.3-2.el8.s390x.rpm libldb-debugsource-2.1.3-2.el8.s390x.rpm libldb-devel-2.1.3-2.el8.s390x.rpm python3-ldb-2.1.3-2.el8.s390x.rpm python3-ldb-debuginfo-2.1.3-2.el8.s390x.rpm
x86_64: ldb-tools-2.1.3-2.el8.x86_64.rpm ldb-tools-debuginfo-2.1.3-2.el8.i686.rpm ldb-tools-debuginfo-2.1.3-2.el8.x86_64.rpm libldb-2.1.3-2.el8.i686.rpm libldb-2.1.3-2.el8.x86_64.rpm libldb-debuginfo-2.1.3-2.el8.i686.rpm libldb-debuginfo-2.1.3-2.el8.x86_64.rpm libldb-debugsource-2.1.3-2.el8.i686.rpm libldb-debugsource-2.1.3-2.el8.x86_64.rpm libldb-devel-2.1.3-2.el8.i686.rpm libldb-devel-2.1.3-2.el8.x86_64.rpm python3-ldb-2.1.3-2.el8.i686.rpm python3-ldb-2.1.3-2.el8.x86_64.rpm python3-ldb-debuginfo-2.1.3-2.el8.i686.rpm python3-ldb-debuginfo-2.1.3-2.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:4568-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:4568
Issued Date: : 2020-11-03
CVE Names: CVE-2020-10730

Topic

An update for libldb is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

1817567 - Rebase libldb to the version required by Samba

1849489 - CVE-2020-10730 samba: NULL pointer de-reference and use-after-free in Samba AD DC LDAP Server with ASQ, VLV and paged_results