Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 12 articles for you...
89

Fedora 43 389-ds-base Security Advisory 2026-27ce708600

New minor version of the Python interpreter, bringing also security fixes. 389-ds-base: Fix system index configuration issues 389-ds-base: Fix AttributeError: 'CustomHelpFormatter' object has no attribute '_format_actions_usage'. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-27ce708600 2026-02-26 01:08:36.076630+00:00 -------------------------------------------------------------------------------- Name : 389-ds-base Product : Fedora 43 Version : 3.1.4 Release : 7.fc43 URL : https://www.port389.org Summary : 389 Directory Server (base) Description : 389 Directory Server is an LDAPv3 compliant server. The base package includes the LDAP server and command line utilities for server administration. -------------------------------------------------------------------------------- Update Information: New minor version of the Python interpreter, bringing also security fixes. 389-ds-base: Fix system index configuration issues 389-ds-base: Fix AttributeError: 'CustomHelpFormatter' object has no attribute '_format_actions_usage' -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 13 2026 Viktor Ashirov - 3.1.4-7 - Issue 7253 - ipa-backup broken with python3-libs-3.14.3-1.fc43 * Wed Feb 11 2026 Viktor Ashirov - 3.1.4-6 - Add missing upgrade steps to %post * Tue Feb 10 2026 Viktor Ashirov - 3.1.4-5 - Fix system index configuration issues -------------------------------------------------------------------------------- References: [ 1 ] Bug #2424574 - 389-ds-base fails to build with Python 3.15: AttributeError: 'CustomHelpFormatter' object has no attribute '_format_actions_usage' https://bugzilla.redhat.com/show_bug.cgi?id=2424574 [ 2 ] Bug #2431825 - CVE-2025-11468 python3.14: Missing character filtering in Python [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431825 [ 3 ] Bug #2431837 -CVE-2026-0672 python3.14: Header injection in http.cookies.Morsel in Python [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431837 [ 4 ] Bug #2431838 - CVE-2026-0865 python3.14: wsgiref.headers.Headers allows header newline injection in Python [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431838 [ 5 ] Bug #2431851 - CVE-2025-15282 python3.14: Header injection via newlines in data URL mediatype in Python [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431851 [ 6 ] Bug #2433829 - CVE-2026-1299 python3.14: email header injection due to unquoted newlines [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2433829 [ 7 ] Bug #2436933 - ipa-healthcheck claims that system indexes are missing or incorrect https://bugzilla.redhat.com/show_bug.cgi?id=2436933 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-27ce708600' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Fedora 43389-ds-base addresses security and system configuration issues in Python interpreter.. Fedora 389-ds-base update, Python security fixes, LDAP server fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 26, 2026 Important Fedora
98

Red Hat 8 RHSA-2023-4655-01 Moderate: Directory Server Security Fix

An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.6 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: redhat-ds:11 security, bug fix, and enhancement update Advisory ID: RHSA-2023:4655-01 Product: Red Hat Directory Server Advisory URL: https://access.redhat.com/errata/RHSA-2023:4655 Issue date: 2023-08-15 CVE Names: CVE-2023-1055 ===================================================================== 1. Summary: An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.6 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Directory Server 11.6 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(s): * RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute (CVE-2023-1055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Users of Red Hat Directory Server 11 are advised to upgrade to these updated packages. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2168719 - lib389 password policy DN handling is incorrect 2173517 - CVE-2023-1055 RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute 6. Package List: Red Hat Directory Server 11.6 for RHEL 8: Source: 389-ds-base-1.4.3.34-1.module+el8dsrv+18380+8350b80e.src.rpm noarch: cockpit-389-ds-1.4.3.34-1.module+el8dsrv+18380+8350b80e.noarch.rpm python3-lib389-1.4.3.34-1.module+el8dsrv+18380+8350b80e.noarch.rpm x86_64: 389-ds-base-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-debugsource-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-devel-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-libs-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-snmp-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.3.34-1.module+el8dsrv+18380+8350b80e.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-1055 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/cve/CVE-2023-1055 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk24qZAAoJENzjgjWX9erEmCIP/AmA/1/kGxF8ACrP6GFQ+pCL xPjbaBzDbz9LlHFyUC7cnyPUIFro80TXBB4P/H1fc1koeZ2yF0KAEBsIzKnocI9H SKJllWkP3C1a0mPjaNZ4N84wYRKEfNJ2IucUpfGZKLcJ8rxomoSdpOMLaZqHm3px E0JC0Vv88XUARwGeuVKtI+6j6Ou5FzNoCd4Kd1XvrMzv7KAbVJxkB9Xoenf8ZbUp NuLV8qiPBCHkrsbE+fMBQ6B5vbOgzX3hPUf/jPIdusGX82FRnqUf/gambzmnuUDq gihVYAWwnl+wzYKHvQpvGdJlxNYonxnuKfyNJc6Q469AKobGTiAvrFz0qy6Gbfv/ hodfwNF5fJc0E/62518Qq72mTmYBECIvK17kmnqhkFlS2x9luaGQ31R8Qlxi88z0 b+klA6RdNdL8bf9NF20ti4z949aIJSzDcNtXoVk8ysxBPB6hCxM+7qjY6PVGY3VH 8C7CgOyy1Oruq1SNJOR7RxCSsTbf9RwUrgpvf7ySaDUNf/pQJVyS++UR5IDvEjnv XJg3dIIYwS8ePiQy8EKgS6UNS/9xv/PH5hRgcK8qepkpb9inkO9Ky6fK/9oReRU3 +nQQZuUvmw4lW+HpawT99/Mi1m1A+y74FN+Z+OtscGRan35ub5rC1CNp8yIHkZvm 16T5+anvXr2FBWHheGsu =csV1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Alert: Security bulletin for Red Hat Directory Server version 11.6 highlights moderate-risk vulnerabilities. Updates and mitigation steps are accessible.. Red Hat Directory Server, Redhat DS, LDAP Security, Security Advisory, Bug Fixes. . LinuxSecurity.com Team

Calendar 2 Aug 15, 2023 Red Hat
98

Red Hat: RHSA-2023-0479-01 Moderate: Directory Server 12 SIGSEGV

An update for the redhat-ds:12 module is now available for Red Hat Directory Server 12.0 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: redhat-ds:12 security update Advisory ID: RHSA-2023:0479-01 Product: Red Hat Directory Server Advisory URL: https://access.redhat.com/errata/RHSA-2023:0479 Issue date: 2023-01-26 CVE Names: CVE-2022-2850 ==================================================================== 1. Summary: An update for the redhat-ds:12 module is now available for Red Hat Directory Server 12.0 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Directory Server 12.0 for RHEL 9 - noarch, x86_64 3. Description: Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(es): * 389-ds-base: SIGSEGV in sync_repl (CVE-2022-2850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2118691 - CVE-2022-2850 389-ds-base: SIGSEGV in sync_repl 6. Package List: Red HatDirectory Server 12.0 for RHEL 9: Source: 389-ds-base-2.0.18-3.module+el9dsrv+17947+6e05a0b8.src.rpm noarch: cockpit-389-ds-2.0.18-3.module+el9dsrv+17947+6e05a0b8.noarch.rpm python3-lib389-2.0.18-3.module+el9dsrv+17947+6e05a0b8.noarch.rpm x86_64: 389-ds-base-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-debuginfo-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-debugsource-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-devel-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-libs-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-libs-debuginfo-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-snmp-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm 389-ds-base-snmp-debuginfo-2.0.18-3.module+el9dsrv+17947+6e05a0b8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2850 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY9L/8dzjgjWX9erEAQjTLBAAkZQjEy/tq1Luvcb4rd9zXumUsYVgyFxe cfStYEZqNkgFL7boP7FCg0oC52GlH41HGL5bvKH+UzEX2rx3w+C+zsawDk1j7ddY 9615Mx4t2pVyMxKzQ/l/sj2HBPAWHcULPPEAnxLdC8A3PpVFc/CMdDDQbq8kEOJL Q/xEyNjwNt7g/mGPDMsVcn7v4w0I3fxOkuKSvaQ9q/UR6Mut08arOFsiHTsIIOLu zHKf6ojW44bLREv8JJLHWsObEwAsrdLvglm1s136iUXkHKc4FuOGgNS2+OLgmJzu POnbqTURlboTfDl7IRBtZtPD7TkwP67dXR/R9uJ7BgADBWUOHSYu1CbTjCuEBW4g S23PRCg1wjAWlAAcxdnyIvf33fTWEg1dL3zE0FUWX+P1fzb2D4YXSTaMlPncSW42 fa5GF2KRMjiStKcVfdjo7qZQHr1BsR3jTBSzVRDLSsgQPE/2pG86I8nw8pec0NTA UZQqW/JBLbicja7sJbS57Yd1CxgXjeNFC5tUlPTfme5Gwc0C8+MsdjwDDfsjnZMk Kcnv9obtv/tUpaXz6Hem8PjleCN0sS/Sn7c4q8ymoGVbKsfZqqYYQ6m6pXnw1Dxh k33B0mbpNlwnGx3tB3eqY4dD8hCnTGagORBPBECNiWVR/mereB7BClZ0TPjyz7jE I3UpPseSSlw=Ns6O -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . RHSA-2023-0480-01 introduces a significant enhancement for Red Hat Identity Management 3.1. Explore the potential security ramifications today.. Red Hat Update, Directory Server Security, RHSA Advisory, LDAP Security, Security Impact. . LinuxSecurity.com Team

Calendar 2 Jan 26, 2023 Red Hat
98

Red Hat Directory Server 11: RHSA-2022-8886-01 Moderate: SIGSEGV Issue

An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.5 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: redhat-ds:11 security, bug fix, and enhancement update Advisory ID: RHSA-2022:8886-01 Product: Red Hat Directory Server Advisory URL: https://access.redhat.com/errata/RHSA-2022:8886 Issue date: 2022-12-07 CVE Names: CVE-2022-2850 ==================================================================== 1. Summary: An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.5 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Directory Server 11.5 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(es): * 389-ds-base: SIGSEGV in sync_repl (CVE-2022-2850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * broken nsslapd-subtree-rename-switch option in rhds11 (BZ#2098140) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 2098140 - broken nsslapd-subtree-rename-switch option in rhds11 2118691 - CVE-2022-2850 389-ds-base: SIGSEGV in sync_repl 6. Package List: Red Hat Directory Server 11.5 for RHEL 8: Source: 389-ds-base-1.4.3.29-7.module+el8dsrv+17334+74991258.src.rpm noarch: cockpit-389-ds-1.4.3.29-7.module+el8dsrv+17334+74991258.noarch.rpm python3-lib389-1.4.3.29-7.module+el8dsrv+17334+74991258.noarch.rpm x86_64: 389-ds-base-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-debuginfo-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-debugsource-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-devel-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-libs-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-snmp-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.3.29-7.module+el8dsrv+17334+74991258.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2850 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/cve/CVE-2022-2850 https://access.redhat.com/security/updates/classification 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY5Ec39zjgjWX9erEAQj30Q//a7zBBR8pjLXTACfSbcwhpI6r1jGbdHjo APENIq04W1TX/aVTNDMGcQsWMQe/IjoPwcwF0MLCyll6tkPPyEN8CJPL1m8vWZru mg0pIAeiGLr6dFYk0Ob3pWQwSlA7WSEOXIyljVj/p5cKzsJdYKJI65obMBvCGz4Z 3ptbyEOl6GRcJS2ZD0S+2CEyDdRPzpQAWMSRHdBR2bNBf26Tox0pURbYjtFTInyE eKAL/BG1r9OrXCDGZMu2TOtCjSdLuajGjw9fYqf7tMxSzAV9w4bkr5Dpfg77fbWr k8YhbxA62jrxnq+WdXWcmJr5YqSwLqd1mCQQYW5fc5zne5Z4e+e4lHHwD4nXrMHE il95cmV+m8W8S2K+/cTINhJKYMVe0mM0pEu5QjeWe7HQTCRTdFBE+eblGejIxS2I bxt1CJJTe9GXVu56PHnnoAH1qks/rj9lZ8+3OxAC1UW/FySBDyApfE7KH3G783LH Ce2b58CfOTTJXTuYkBE9v3LMhiKFA1rzX2hJygZk7gSjxDFXBVJRS3YZ1dw0MInB umDRK2AMThYZ+00slUjtyPt88st4zts09odvJIMUAaB4GNcfqdr1zS4S3xp89NwL C5GnuIkGu/dC7ywF1HMBpZVEqRZ9/Tvtokb8y8W0n03F5io/IE9OjkgqGImx0SoK /TWchSuawp4=uXkN -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Revised redhat-ds:11 module for Red Hat Directory Server 11.5 mitigates moderate security risks and resolves existing bugs.. Red Hat Directory Server, LDAP update, security advisory, bug fixes. . LinuxSecurity.com Team

Calendar 2 Dec 07, 2022 Red Hat
98

Red Hat 8.4 RHSA-2022-1410-01 Low: 389-ds Double Free Issue

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: 389-ds:1.4 security and bug fix update Advisory ID: RHSA-2022:1410-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:1410 Issue date: 2022-04-19 CVE Names: CVE-2021-4091 ==================================================================== 1. Summary: An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): * 389-ds-base: double free of the virtual attribute context in persistent search (CVE-2021-4091) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * DB corruption "_entryrdn_insert_key - Same DN (dn: nsuniqueid=ffffffff-ffffffff-ffffffff-ffffffff, ) is already in the entryrdn file" (BZ#2066800) * IPA server (389ds) is very slow in execution of somesearches (`&(memberOf=...)(objectClass=ipaHost)` in particular) (BZ#2066801) * monitor displays wrong date for connection (BZ#2066848) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2030307 - CVE-2021-4091 389-ds-base: double free of the virtual attribute context in persistent search 2066800 - DB corruption "_entryrdn_insert_key - Same DN (dn: nsuniqueid=ffffffff-ffffffff-ffffffff-ffffffff, ) is already in the entryrdn file" 2066801 - IPA server (389ds) is very slow in execution of some searches (`&(memberOf=...)(objectClass=ipaHost)` in particular) 2066848 - monitor displays wrong date for connection 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.4): Source: 389-ds-base-1.4.3.16-20.module+el8.4.0+14552+b182c759.src.rpm aarch64: 389-ds-base-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-debugsource-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-devel-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-legacy-tools-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-libs-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-libs-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-snmp-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm 389-ds-base-snmp-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.aarch64.rpm noarch: python3-lib389-1.4.3.16-20.module+el8.4.0+14552+b182c759.noarch.rpm ppc64le: 389-ds-base-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-debugsource-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-devel-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-legacy-tools-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-libs-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-libs-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-snmp-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm 389-ds-base-snmp-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.ppc64le.rpm s390x: 389-ds-base-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-debugsource-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-devel-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-legacy-tools-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-libs-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-libs-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-snmp-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm 389-ds-base-snmp-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.s390x.rpm x86_64: 389-ds-base-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-debugsource-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-devel-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-libs-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-snmp-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.3.16-20.module+el8.4.0+14552+b182c759.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-4091 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYl7ul9zjgjWX9erEAQhcxg/9HAutJcNWHFMbkpHZEZupCBTm+F+4hV4X 7RpRa+QZv35GBEYMPPcdG6fGQ+HizL6JXYJ7PoMh4Tk4yvLLSDbV/DgGAu6otfMg w6rY3LYC8NK2ddQmU5ERGU6SH8o0SCV++hMznrwEJYGIsmAQ5K3Iwh4umszrjNfF 5dTrCRDrPJKh8ToXKa99D5vC3WMHLFbNrHl3KQJLvFMEc7q5IkRB7X8wSY6flBml CGoR49DjTGVeD746+n3il58ShxaTqq2e2MPl5ipKjGtsLmxaTPPvqzPlgvchyIuO Czp9glJy6bhe2JnYGZf4nKLmlZCjm5d4CvAr1HzTvzymwrCVUnbLfHuRbBYZnoU8 p1wZUJJXummvngFjCGO7+oOKA5B13ZvJ6qSQJVRBu1r8LyTgFKLyUr5AgvZhAw0N nJklqR9dOnpdFLEHyx9O3lDtD+K1mRndUvBpY4JtMYwqs8yMlvGabnahHvhdoCJ7 6tbr6F+x3o20zfA/4FvEopNUxoFjI8c07hK4UIdusH+x3veyH/MMMfLz35172/FW 0MCJ/1fS4tROH7L9pJhTecL49cQTntGfMf4TjKQO68fz34mjglOxRbVI84Yz92rz F1bdxx8jc4ZLBfB4rTTvOsx4Hq2wAMqPZAEqDFilnx/viToRvbxkqbl3RCpr5FX6 a9hoUJbZW40=w/jo -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Red Hat releases a Minor security advisory for 389-ds:1.4 addressing various bug issues; discover further information regarding the update.. Red Hat, 389-ds, security update, LDAP server, bug fixes. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Apr 19, 2022 Low Red Hat
89

Fedora 35: Resolving Moderate LDAP Access Issue in 389-ds-base 2022-40544

Bump version to 2.0.15. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-40544b5314 2022-04-01 04:50:46.205439 --------------------------------------------------------------------------------Name : 389-ds-base Product : Fedora 35 Version : 2.0.15 Release : 1.fc35 URL : https://www.port389.org Summary : 389 Directory Server (base) Description : 389 Directory Server is an LDAPv3 compliant server. The base package includes the LDAP server and command line utilities for server administration. --------------------------------------------------------------------------------Update Information: Bump version to 2.0.15 --------------------------------------------------------------------------------ChangeLog: * Wed Mar 23 2022 Mark Reynolds - 2.0.15-1 - Bump version to 2.0.15 - Issue 5230 - Race condition in RHDS disk monitoring functions - Issue 4299 - UI - Add CoS funtionality (#5196) - Issue 5225 - UI - impossible to manually set entry cache - Issue 5186 - UI - Fix SASL Mapping regex test feature - Issue 5221 - User with expired password can still login with full privledges - Issue 5218 - double-free of the virtual attribute context in persistent search (#5219) - Issue 5200 - dscontainer should use environment variables with DS_ prefix - Issue 5193 - Incomplete ruv occasionally returned from ruv search (#5194) - Issue 5189 - memberOf plugin exclude subtree not cleaning up groups on modrdn - Issue 5188 - UI - LDAP editor - add entry and group types - Issue 5184 - memberOf does not work correctly with multiple include scopes - Issue 5162 - BUG - error on importing chain files (#5164) - Issue 5186 - UI - Fix SASL Mapping regex validation and other minor improvements - Issue 5048 - Support for nsslapd-tcp-fin-timeout and nsslapd-tcp-keepalive-time (#5179) - Issue 5122 - dsconf instance backend suffix set doesn't accept backend name (#5178) - Issue 5160 - BUG - x- prefix in descr-oidcan confuse oid parser (#5161) - Issue 5098 - Multiple issues around replication and CI test test_online_reinit_may_hang (#5109) - Issue 5102 - BUG - container may fail with bare uid/gid (#5140) - Issue 5137 - RFE - improve sssd conf output (#5138) - Issue 5145 - Fix covscan errors - Issue 4721 - UI - attribute uniqueness crashes UI when there are no configs - Issue 5155 - RFE - Provide an option to abort an Auto Member rebuild task - Issue 4299 - UI - Add Role funtionality (#5163) - Issue 5050 - bdb bulk op fails if fs page size > 8K (#5150) - Issue 4775 - Add entryuuid CLI and Fixup (#4776) - Issue 5142 - CLI - dsctl dbgen is broken - Issue 4299 - UI - fix minor issues with ldap editor (table view) - Issue 4299 - UI - fix minor issues with ldap editor - Issue 5103 - UI - Add support for TPR to web console (#5111) --------------------------------------------------------------------------------References: [ 1 ] Bug #2066142 - CVE-2022-0996 389-ds-base: expired password was still allowed to access the database [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2066142 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-40544b5314' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Latest Fedora 35 iteration for 389-ds-base enhances LDAP server capabilities and addresses multiple concerns.. Fedora Update, 389 Directory Server, LDAP Security Fix, Software Improvement. . LinuxSecurity.com Team

Calendar 2 Apr 01, 2022 Fedora
98

Red Hat 8.2: RHSA-2021-2796 Moderate: 389-ds NULL Pointer Issue

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: 389-ds:1.4 security update Advisory ID: RHSA-2021:2796-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2796 Issue date: 2021-07-20 CVE Names: CVE-2021-3514 ==================================================================== 1. Summary: An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.2) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): * 389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control() (CVE-2021-3514) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1952907 -CVE-2021-3514 389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control() 1960723 - CVE-2021-3514 389-ds:1.4/389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control() [rhel-8] [rhel-8.2.0.z] 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.2): Source: 389-ds-base-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.src.rpm aarch64: 389-ds-base-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-debugsource-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-devel-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-legacy-tools-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-libs-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-libs-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-snmp-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm 389-ds-base-snmp-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.aarch64.rpm noarch: python3-lib389-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.noarch.rpm ppc64le: 389-ds-base-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-debugsource-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-devel-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-legacy-tools-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-legacy-tools-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-libs-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-libs-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-snmp-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm 389-ds-base-snmp-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.ppc64le.rpm s390x: 389-ds-base-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-debugsource-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-devel-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-legacy-tools-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-legacy-tools-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-libs-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-libs-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-snmp-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm 389-ds-base-snmp-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.s390x.rpm x86_64: 389-ds-base-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-debugsource-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-devel-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-legacy-tools-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-libs-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-snmp-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.2.4-14.module+el8.2.0+11017+0eb5711a.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-3514 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYPdjC9zjgjWX9erEAQh3MRAAobWePNHm8HVAc6+VTc79y52dFYMLbxx8 /dpJW6OQDmGeT/S8PofHgY0g1z7YJwEkpA5YXmVptu5bLV6ZTk2QSwOvHzP9mZxm QRUTPXQHBXVtZWkSYaYxkR0mh2Cbht1ZrikJDu7OAGiDBYmbg5EYMO0v/2RUjhJL 525PSbEOIgRobZE2+7IV0Z56MuZpmRWDJeF1r+kgQmttm4srh7DXJyzqShkqcyEA XOaRBuHgifQ8gUcU/Fp2lDl/j/sTuFVOahrUb4QGCdQPSz+ejGslxsQjqHB9KiY3 c17MUtwt6Ym9c8srsormNYsbpez2IntKUHtsbUbprY8s9NwLi7hmU55xwZeAdw99 PtLj54IZnrQo0lqp7/YWZhZcE0/JEvMKk0lJHQBXcQYRaHScZnOvr0qtvjgVDi8H fijAXiu6YbZvKUwINuZInX8wIuuLDcvFFXOyzc8inaUk65n6xeg2wk0mBeGr3FH/ glg2uTOIXEb6k2dxbOMxxbM4am91WUFZ2qN3DNKqyeMdApVxDJNg1sgwzBsHlfrd nAT+ARQDgAZnw5tTVxwfe4nBuKbqWo1jmzGrhM392KQCiaazN+ktzGRMMB6QYDJQ yhtpW/MoTpi3ycpF+eDE6gFC9FEmsm0fZ7TYGuerolObV/z4rx5xqYBJEGmd3oN8 Tr8C0KsBJzA=xM+t -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat releases a noteworthy security patch for 389-ds:1.4 in RHEL 8.2, addressing severe NULL pointer vulnerabilities.. Red Hat Security, LDAP Security, 389 Directory Server Update. . LinuxSecurity.com Team

Calendar 2 Jul 20, 2021 Red Hat
98

Red Hat Directory Server 11 RHSA-2021:1243-01 Moderate Info Leak

An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.2 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: redhat-ds:11 security and bug fix update Advisory ID: RHSA-2021:1243-01 Product: Red Hat Directory Server Advisory URL: https://access.redhat.com/errata/RHSA-2021:1243 Issue date: 2021-04-19 CVE Names: CVE-2020-35518 ==================================================================== 1. Summary: An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.2 for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Directory Server 11.2 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(es): * 389-ds-base: information disclosure during the binding of a DN (CVE-2020-35518) (BZ#1905565) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * The UI become unresponsive when an error occured (BZ#1751082) * The python-lib389 class Accounts displayed an error during delete operations (BZ#1859215) * The server version number has been added to the UI(BZ#1859288) * Searches by an unauthorized client can no longer determine if an entry exists or not by the result code (BZ#1925537) * Changes made on the Server Tuning page in the web console are now correctly reflected (BZ#1927051) * Adding new schema using dsconf no longer displayes a "values has to be a tuple" error (BZ#1937036) Users of Red Hat Directory Server 11 are advised to install these updated packages. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1751082 - Red Hat Directory Server page gets into an unresponsive loading state forever 1859215 - lib389 Issue: With Accounts/Account module delete fuction is not working 1859288 - add version information for 389-ds-base and RHDS to cli and cockpit 1905565 - CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN 1925537 - RHDS11: “write” permission of ACI changes ns-slapd’s behavior on search operation 1927051 - Changes in the "Tuning & Limits" are saved in LDAP but the Console shows the previous value. 1930272 - CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN [directory_server_11] 1937036 - Error "values has to be a tuple" when creating schema using dsconf [RHDS 11.2] 6. Package List: Red Hat Directory Server 11.2 for RHEL8: Source: 389-ds-base-1.4.3.21-3.module+el8dsrv+10401+3d549418.src.rpm noarch: cockpit-389-ds-1.4.3.21-3.module+el8dsrv+10401+3d549418.noarch.rpm python3-lib389-1.4.3.21-3.module+el8dsrv+10401+3d549418.noarch.rpm x86_64: 389-ds-base-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-debuginfo-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-debugsource-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-devel-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-legacy-tools-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-legacy-tools-debuginfo-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-libs-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-libs-debuginfo-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-snmp-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm 389-ds-base-snmp-debuginfo-1.4.3.21-3.module+el8dsrv+10401+3d549418.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-35518 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYH1ThtzjgjWX9erEAQi+qhAAlTYiNPXGmiXwpDG7HikOpaP5Rxm4/kZa gRz04jLMGtyd3YRQYpDrPWP6UDUm2efzTQlWm6yWCJ/6SzLdyOIgvU0lYpoDtQFQ RBdu99G8MrG/7ZTUw4eKTfLtrYLRHa7ba0HDebX2iXNx9AtSm0gIvUZOIurHAIMX 8h9ISS85PkLwLzwibtGZQ5oDmwkbXavy0i3IHhwo3VpGakyaHqgnh214djkPF9wt yD3itz3bp9QfoVE+WvTEFo8kMz8kMP5oB2G5ERJSXs5Wv3431Gje+xUO7Widj7Mk wsaK6LXV3NVVrKg307Ots4ypIg8+ZulAmonUEaPDMVgKzl9q3+U5eAZOv3X+I9sM a63RHbjIFdd11mehOL8dW42H1jGj4gTBwYOclD3z6n8kRPzb5mr+pBoFnbakR3Xv L99S0rsAo4Qg/6hZtGDq/P62JohrHwb4oonquXJthbJi3mKIyUrxNiruW5FKQt9P xxov2nT+W0b3p9TDh5r+UJisrn16Z0NVS+GUn4p2r2Tn9YB6q7qsonm/xSin3qLs nKYUwGcEDdLleElI8Rabmt5Vazv/il0gMf5HJl/pEjhJ0yV3OWo9dJGb6BlALpaL LP1hzvYOaJe0DlqeXspjZ/qGEo3vNDHMMOKDPp9c0wbed3gQB8ntMGYBeuuAEYXQ YCHfBIe0op0=HmnC -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . The latest release of Red Hat Directory Server 11 tackles several notable security concerns and incorporates performance enhancements through various bug fixes.. Red Hat Directory Server, security update, LDAP server, bug fixes, administration. . LinuxSecurity.com Team

Calendar 2 Apr 19, 2021 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here