SUSE-SU-2022:3029-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3029-1
SUSE-SU-2022:3029-1
Summary: Security update for 389-ds
Details: This update for 389-ds fixes the following issues: - CVE-2022-2850: Fixed an application crash when running a sync_repl client that could be triggered via a malformed cookie (bsc#1202470). Non-security fixes: - Update to version 1.4.4.19~git46.c900a28c8: * CI - makes replication/acceptance_test.py::test_modify_entry more robust * UI - LDAP Editor is not updated when we switch instances - Improvements to openldap import with password policy present (bsc#1199908) - Update to version 1.4.4.19~git43.8ba2ea21f: * fix covscan * BUG - pid file handling * Memory leak in slapi_ldap_get_lderrno * Need a compatibility option about sub suffix handling * Release tarballs don't contain cockpit webapp * Replication broken after password change * Harden ReplicationManager.wait_for_replication * dscontainer: TypeError: unsupported operand type(s) for /: 'str' and 'int' * CLI - dsconf backend export breaks with multiple backends * CLI - improve task handling
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223029-1/, https://bugzilla.suse.com/1199908, https://bugzilla.suse.com/1202470, https://www.suse.com/security/cve/CVE-2022-2850
Affected packages
Package
Name: 389-ds
Purl: pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
