Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2022:0013
Issued: 2022-02-24
Updated: 2022-02-24
Summary
openldap security update
Severity
Moderate
Description
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:
CVE-2020-25709:
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
CVE-2020-25710:
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
References
Updated Packages
- aarch64
- openldap-2.4.44-25.1.al7.aarch64.rpm → (download)
- openldap-clients-2.4.44-25.1.al7.aarch64.rpm → (download)
- openldap-debuginfo-2.4.44-25.1.al7.aarch64.rpm → (download)
- openldap-devel-2.4.44-25.1.al7.aarch64.rpm → (download)
- openldap-servers-2.4.44-25.1.al7.aarch64.rpm → (download)
- openldap-servers-sql-2.4.44-25.1.al7.aarch64.rpm → (download)
- i686
- openldap-2.4.44-25.1.al7.i686.rpm → (download)
- openldap-clients-2.4.44-25.1.al7.i686.rpm → (download)
- openldap-debuginfo-2.4.44-25.1.al7.i686.rpm → (download)
- openldap-devel-2.4.44-25.1.al7.i686.rpm → (download)
- openldap-servers-2.4.44-25.1.al7.i686.rpm → (download)
- openldap-servers-sql-2.4.44-25.1.al7.i686.rpm → (download)
- src
- openldap-2.4.44-25.1.al7.src.rpm → (download)
- x86_64
- openldap-2.4.44-25.1.al7.x86_64.rpm → (download)
- openldap-clients-2.4.44-25.1.al7.x86_64.rpm → (download)
- openldap-debuginfo-2.4.44-25.1.al7.x86_64.rpm → (download)
- openldap-devel-2.4.44-25.1.al7.x86_64.rpm → (download)
- openldap-servers-2.4.44-25.1.al7.x86_64.rpm → (download)
- openldap-servers-sql-2.4.44-25.1.al7.x86_64.rpm → (download)