UbuntuUpdates.org

Package "ldb"

Name: ldb

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • LDAP-like embedded database - tools

Latest version: 2:1.2.3-1ubuntu0.2
Release: bionic (18.04)
Level: updates
Repository: universe

Links



Other versions of "ldb" in Bionic

Repository Area Version
base main 2:1.2.3-1
base universe 2:1.2.3-1
security main 2:1.2.3-1ubuntu0.2
security universe 2:1.2.3-1ubuntu0.2
updates main 2:1.2.3-1ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:1.2.3-1ubuntu0.2 2021-03-24 20:07:11 UTC

  ldb (2:1.2.3-1ubuntu0.2) bionic-security; urgency=medium

  * SECURITY UPDATE: Heap corruption via crafted DN strings
    - debian/patches/CVE-2020-27840.patch: avoid head corruption in
      ldb_dn_explode in common/ldb_dn.c.
    - CVE-2020-27840
  * SECURITY UPDATE: Out of bounds read in AD DC LDAP server
    - debian/patches/CVE-2021-20277.patch: stay in bounds in
      common/attrib_handlers.c.
    - CVE-2021-20277

 -- Marc Deslauriers <email address hidden> Wed, 24 Mar 2021 08:03:16 -0400

Source diff to previous version
CVE-2020-27840 Heap corruption via crafted DN strings
CVE-2021-20277 Out of bounds read in AD DC LDAP server

Version: 2:1.2.3-1ubuntu0.1 2019-02-26 19:07:41 UTC

  ldb (2:1.2.3-1ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Out of bound read in ldb_wildcard_compare
    - debian/patches/CVE-2019-3824-1.patch: fix length.
    - debian/patches/CVE-2019-3824-2.patch: add extra comments.
    - debian/patches/CVE-2019-3824-3.patch: improve code style.
    - debian/patches/CVE-2019-3824-4.patch: use talloc_zero.
    - debian/patches/CVE-2019-3824-5.patch: check tree operation.
    - debian/patches/CVE-2019-3824-6.patch: fix end of data check.
    - CVE-2019-3824

 -- Marc Deslauriers <email address hidden> Mon, 25 Feb 2019 08:13:32 -0500

CVE-2019-3824 Out of bound read in ldb_wildcard_compare



About   -   Send Feedback to @ubuntu_updates