=========================================================================Ubuntu Security Notice USN-6197-1
July 03, 2023

openldap vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

OpenLDAP could be made to crash if it received specially crafted
input.

Software Description:
- openldap: Lightweight Directory Access Protocol

Details:

It was discovered that OpenLDAP was not properly performing bounds checks
when executing functions related to LDAP URLs. An attacker could possibly
use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
   slapd                           2.4.45+dfsg-1ubuntu1.11+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
   slapd                           2.4.42+dfsg-2ubuntu3.13+esm2

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
   slapd                           2.4.31-1+nmu2ubuntu8.5+esm6

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6197-1
   CVE-2023-2953

Ubuntu 6197-1: OpenLDAP vulnerability

July 3, 2023
OpenLDAP could be made to crash if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro):   slapd                           2.4.45+dfsg-1ubuntu1.11+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro):   slapd                           2.4.42+dfsg-2ubuntu3.13+esm2 Ubuntu 14.04 LTS (Available with Ubuntu Pro):   slapd                           2.4.31-1+nmu2ubuntu8.5+esm6 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6197-1

  CVE-2023-2953

Severity
July 03, 2023

Package Information

Related News