SUSE-SU-2022:1832-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1832-1
SUSE-SU-2022:1832-1
Summary: Security update for openldap2
Details: This update for openldap2 fixes the following issues: Security: - CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240). Bugfixes: - allow specification of max/min TLS version with TLS1.3 (bsc#1191157) - libldap was able to be out of step with openldap in some cases which could cause incorrect installations and symbol resolution failures. openldap2 and libldap now are locked to their related release versions. (bsc#1197004) - restore CLDAP functionality in CLI tools (jsc#PM-3288)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221832-1/, https://bugzilla.suse.com/1191157, https://bugzilla.suse.com/1197004, https://bugzilla.suse.com/1199240, https://www.suse.com/security/cve/CVE-2022-29155
Affected packages
Package
Name: openldap2
Purl: pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
