SUSE-SU-2019:0931-1
Dashboard / Vulnerabilities / SUSE-SU-2019:0931-1
SUSE-SU-2019:0931-1
Summary: Security update for openldap2
Details: This update for openldap2 fixes the following issues: Security issues fixed: - CVE-2017-9287: A double free vulnerability in the mdb backend during search with page size 0 was fixed (bsc#1041764). - CVE-2017-17740: Fixed a denial of service (slapd crash) via a member MODDN operation that could have been triggered when both the nops module and the memberof overlay are enabled (bsc#1073313). Non-security issues fixed: - Fix a regression in handling of non-blocking connections (bsc#1031702) - Fix an uninitialised variable that causes startup failure (bsc#1037396) - Fix libldap leaks socket descriptors issue (bsc#1065083)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20190931-1/, https://bugzilla.suse.com/1031702, https://bugzilla.suse.com/1037396, https://bugzilla.suse.com/1041764, https://bugzilla.suse.com/1065083, https://bugzilla.suse.com/1073313, https://www.suse.com/security/cve/CVE-2017-17740, https://www.suse.com/security/cve/CVE-2017-9287
Affected packages
Package
Name: openldap2
Purl: pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012
Affected ranges
Type: ECOSYSTEM
Events:
