UbuntuUpdates.org

Package "freeradius-ldap"

Name: freeradius-ldap

Description:

LDAP module for FreeRADIUS server

Latest version: 2.2.8+dfsg-0.1ubuntu0.1
Release: xenial (16.04)
Level: updates
Repository: universe
Head package: freeradius
Homepage: http://www.freeradius.org/

Links


Download "freeradius-ldap"


Other versions of "freeradius-ldap" in Xenial

Repository Area Version
base universe 2.2.8+dfsg-0.1build2
security universe 2.2.8+dfsg-0.1ubuntu0.1

Changelog

Version: 2.2.8+dfsg-0.1ubuntu0.1 2017-07-27 18:06:56 UTC

  freeradius (2.2.8+dfsg-0.1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: read/write overflow in make_secret()
    - debian/patches/CVE-2017-10978.patch: check lengths in
      src/lib/radius.c.
    - CVE-2017-10978
  * SECURITY UPDATE: write overflow in rad_coalesce
    - debian/patches/CVE-2017-10979.patch: check for long attributes in
      src/lib/dhcp.c, src/lib/radius.c.
    - CVE-2017-10979
  * SECURITY UPDATE: memory leak in decode_tlv()
    - debian/patches/CVE-2017-10980.patch: fix memory leak in
      src/lib/dhcp.c.
    - CVE-2017-10980
  * SECURITY UPDATE: memory leak in fr_dhcp_decode()
    - debian/patches/CVE-2017-10981.patch: fix another memory leak in
      src/lib/dhcp.c.
    - CVE-2017-10981
  * SECURITY UPDATE: read overflow in fr_dhcp_decode_options()
    - debian/patches/CVE-2017-10982.patch: check for long options in
      src/lib/dhcp.c.
    - CVE-2017-10982
  * SECURITY UPDATE: read overflow when decoding option 63
    - debian/patches/CVE-2017-10983.patch: decode correct option in
      src/lib/dhcp.c.
    - CVE-2017-10983

 -- Marc Deslauriers <email address hidden> Wed, 26 Jul 2017 10:32:39 -0400

CVE-2017-1097 RESERVED
CVE-2017-1098 RESERVED



About   -   Send Feedback to @ubuntu_updates