Change logs for openldap source package in Trusty

  • openldap (2.4.31-1+nmu2ubuntu8.5) trusty; urgency=medium
    
      * d/apparmor-profile: update apparmor profile to allow reading of
        files needed when slapd is behaving as a kerberos/gssapi client
        and acquiring its own ticket. (LP: #1783183)
    
     -- Andreas Hasenack <email address hidden>  Mon, 22 Oct 2018 09:49:38 -0300
  • openldap (2.4.31-1+nmu2ubuntu8.4) trusty-security; urgency=medium
    
      * SECURITY UPDATE: denial of service via search with page size of 0
        - debian/patches/CVE-2017-9287.patch: fix double-free in
          servers/slapd/back-mdb/search.c.
        - CVE-2017-9287
    
     -- Marc Deslauriers <email address hidden>  Tue, 30 May 2017 15:24:10 -0400
  • openldap (2.4.31-1+nmu2ubuntu8.3) trusty; urgency=medium
    
      * Fix segfault issue in slap_bv2ad (LP: #1593378)
        - d/p/its-7941-fix-for-repeated-tags.patch: Cherry picked
        patch from upstream VCS.
    
     -- Eric Desrochers <email address hidden>  Fri, 24 Jun 2016 11:05:23 +0200
  • openldap (2.4.31-1+nmu2ubuntu8.2) trusty-security; urgency=medium
    
      * SECURITY UPDATE: denial of service via crafted BER data
        - debian/patches/CVE-2015-6908.patch: remove obsolete assert in
          libraries/liblber/io.c.
        - CVE-2015-6908
      * SECURITY UPDATE: user impersonation via incorrect default permissions
        - debian/slapd.init.ldif: disallow modifying one's own entry by
          default.
        - CVE-2014-9713
    
     -- Marc Deslauriers <email address hidden>  Mon, 14 Sep 2015 10:36:46 -0400
  • openldap (2.4.31-1+nmu2ubuntu8.1) trusty-security; urgency=medium
    
      * SECURITY UPDATE: fix rwm overlay reference counting. (LP: #1446809)
        - debian/patches/CVE-2013-4449.patch: fix reference counting
        - CVE-2013-4449
      * SECURITY UPDATE: fix NULL pointer dereference in deref_parseCtrl()
        - debian/patches/CVE-2015-1545.patch: require non-empty AttributeList
        - CVE-2015-1545
    
     -- Felipe Reyes <email address hidden>  Tue, 19 May 2015 13:00:21 -0300
  • openldap (2.4.31-1+nmu2ubuntu8) trusty; urgency=medium
    
      * Bump database_format_changed value to 2.4.31-1+nmu2ubuntu5 for db5.3.
     -- Adam Conrad <email address hidden>   Mon, 17 Mar 2014 12:50:18 -0600
  • openldap (2.4.31-1+nmu2ubuntu7) trusty; urgency=medium
    
      * Disable mdb backend on ppc64el due to test-suite failures.
     -- Dimitri John Ledkov <email address hidden>   Mon, 17 Mar 2014 16:32:29 +0000
  • openldap (2.4.31-1+nmu2ubuntu6) trusty; urgency=low
    
      * Fix segfault issue with master-master syncrepl (LP: #1287730):
        - d/patches/its-7354-fix-delta-sync-mmr.diff: Cherry picked
          patch from upstream VCS.
     -- Pierre Fersing <email address hidden>   Tue, 04 Mar 2014 16:04:57 +0100
  • openldap (2.4.31-1+nmu2ubuntu5) trusty; urgency=low
    
      * Build-depend on libdb5.3-dev, instead of libdb5.1-dev.
     -- Dmitrijs Ledkovs <email address hidden>   Mon, 04 Nov 2013 08:04:30 +0000
  • openldap (2.4.31-1+nmu2ubuntu4) trusty; urgency=low
    
      * Rebuild for Perl 5.18.
     -- Colin Watson <email address hidden>   Tue, 22 Oct 2013 12:16:39 +0100
  • openldap (2.4.31-1+nmu2ubuntu3) saucy; urgency=low
    
      * Update build/config.guess and build/config.sub at build time; this was
        not done automatically because the top-level configure.in does not use
        Automake.
     -- Colin Watson <email address hidden>   Tue, 08 Oct 2013 17:24:59 +0100