UbuntuUpdates.org

Package "ldb"

Name: ldb

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • LDAP-like embedded database - tools
  • LDAP-like embedded database - development files
  • LDAP-like embedded database - shared library
  • LDAP-like embedded database - debug symbols

Latest version: 1:1.1.4-1ubuntu0.1
Release: precise (12.04)
Level: updates
Repository: universe

Links



Other versions of "ldb" in Precise

Repository Area Version
base universe 1:1.1.4-1
security universe 1:1.1.4-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:1.1.4-1ubuntu0.1 2016-01-05 21:07:03 UTC

  ldb (1:1.1.4-1ubuntu0.1) precise-security; urgency=medium

  * SECURITY UPDATE: denial of service in ldb_wildcard_compare function
    - debian/patches/CVE-2015-3223.patch: handle empty strings and
      embedded zeros in lib/ldb/common/ldb_match.c.
    - CVE-2015-3223
  * SECURITY UPDATE: information leak via incorrect string length handling
    - debian/patches/CVE-2015-5330.patch: fix string length handling in
      lib/ldb/common/ldb_dn.c.
    - CVE-2015-5330

 -- Marc Deslauriers Mon, 04 Jan 2016 10:16:11 -0500

CVE-2015-3223 The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7,
CVE-2015-5330 ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, w



About   -   Send Feedback to @ubuntu_updates