SUSE-SU-2019:2155-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2155-1
SUSE-SU-2019:2155-1
Summary: Security update for 389-ds
Details: This update for 389-ds to version 1.4.0.26 fixes the following issues: Security issues fixed: - CVE-2016-5416: Fixed an information disclosure where a anonymous user could read the default ACI (bsc#991201). - CVE-2018-1054: Fixed a denial of service via search filters in SetUnicodeStringFromUTF_8() (bsc#1083689). - CVE-2018-1089: Fixed a buffer overflow via large filter value (bsc#1092187). - CVE-2018-10871: Fixed an information disclosure in certain plugins leading to the disclosure of plaintext password to an privileged attackers (bsc#1099465). - CVE-2018-14638: Fixed a denial of service through a crash in delete_passwdPolicy () (bsc#1108674). - CVE-2018-14648: Fixed a denial of service caused by malformed values in search queries (bsc#1109609). - CVE-2018-10935: Fixed a denial of service related to ldapsearch with server side sort (bsc#1105606). - CVE-2019-3883: Fixed a denial of service caused by hanging LDAP requests over TLS (bsc#1132385).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192155-1/, https://bugzilla.suse.com/1083689, https://bugzilla.suse.com/1092187, https://bugzilla.suse.com/1099465, https://bugzilla.suse.com/1105606, https://bugzilla.suse.com/1108674, https://bugzilla.suse.com/1109609, https://bugzilla.suse.com/1120189, https://bugzilla.suse.com/1132385, https://bugzilla.suse.com/1144797, https://bugzilla.suse.com/991201, https://www.suse.com/security/cve/CVE-2016-5416, https://www.suse.com/security/cve/CVE-2018-1054, https://www.suse.com/security/cve/CVE-2018-10871, https://www.suse.com/security/cve/CVE-2018-1089, https://www.suse.com/security/cve/CVE-2018-10935, https://www.suse.com/security/cve/CVE-2018-14638, https://www.suse.com/security/cve/CVE-2018-14648, https://www.suse.com/security/cve/CVE-2019-3883
Affected packages
Package
Name: 389-ds
Purl: pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
