Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Bug#1036995: openldap: CVE-2023-2953

38 views
Skip to first unread message

Salvatore Bonaccorso

unread,
May 31, 2023, 3:20:04 PM5/31/23
to
Source: openldap
Version: 2.5.13+dfsg-5
Severity: important
Tags: security upstream
Forwarded: https://bugs.openldap.org/show_bug.cgi?id=9904
X-Debbugs-Cc: car...@debian.org, Debian Security Team <te...@security.debian.org>
Control: fixed -1 2.6.4+dfsg-1~exp1

Hi,

The following vulnerability was published for openldap.

CVE-2023-2953[0]:
| A vulnerability was found in openldap. This security flaw causes a
| null pointer dereference in ber_memalloc_x() function.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-2953
https://www.cve.org/CVERecord?id=CVE-2023-2953
[1] https://bugs.openldap.org/show_bug.cgi?id=9904

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Ryan Tandy

unread,
May 31, 2023, 7:40:04 PM5/31/23
to
Hi, thanks for the report. If I've understood the issue correctly
(DoS/crash if malloc fails), it does not look too urgent.

Although the fixes look safe enough, I think we could wait until after
bookworm is released, and fix this in unstable first and in a point
release later. Does that sound OK to you?

thanks,
Ryan

Salvatore Bonaccorso

unread,
Jun 1, 2023, 1:10:04 AM6/1/23
to
Hi Ryan,

On Wed, May 31, 2023 at 04:34:31PM -0700, Ryan Tandy wrote:
> Hi, thanks for the report. If I've understood the issue correctly (DoS/crash
> if malloc fails), it does not look too urgent.

Correct, agreed.

> Although the fixes look safe enough, I think we could wait until after
> bookworm is released, and fix this in unstable first and in a point release
> later. Does that sound OK to you?

Yes I do agree. The issue can be fixed after the bookworm release for
unstable and trixie, and for bookworm fixing it in the first point
release is absolutely fine. We do not need a DSA here. The same holds
for bullseye.

Thank you for the swift reply back!

Regards,
Salvatore
0 new messages