UbuntuUpdates.org

Package "python-ldap"

Name: python-ldap

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • LDAP interface module (Documentation)
  • LDAP interface module for Python3

Latest version: 3.4.4-1ubuntu0.24.04.1
Release: noble (24.04)
Level: updates
Repository: main

Links



Other versions of "python-ldap" in Noble

Repository Area Version
base universe 3.4.4-1build1
base main 3.4.4-1build1
security main 3.4.4-1ubuntu0.24.04.1
security universe 3.4.4-1ubuntu0.24.04.1
updates universe 3.4.4-1ubuntu0.24.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.4.4-1ubuntu0.24.04.1 2025-10-20 22:11:48 UTC

  python-ldap (3.4.4-1ubuntu0.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: Improper special character escape when supplying
    non-string data types.
    - debian/patches/CVE-2025-61911.patch: Raise exception when type is not str
      in Lib/ldap/filter.py.
    - CVE-2025-61911
  * SECURITY UPDATE: Denial of service through improperly escaped null byte.
    - debian/patches/CVE-2025-61912.patch: Change NULL byte escape from \\\000
      to \\00 in Lib/ldap/dn.py.
    - CVE-2025-61912

 -- Hlib Korzhynskyy <email address hidden> Wed, 15 Oct 2025 15:35:04 -0230

CVE-2025-61911 python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter
CVE-2025-61912 python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x



About   -   Send Feedback to @ubuntu_updates