[SECURITY] Fedora 20 Update: openldap-2.4.39-2.fc20

updates at fedoraproject.org updates at fedoraproject.org
Tue Feb 11 23:13:08 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-2012
2014-02-05 03:00:40
--------------------------------------------------------------------------------

Name        : openldap
Product     : Fedora 20
Version     : 2.4.39
Release     : 2.fc20
URL         : http://www.openldap.org/
Summary     : LDAP support libraries
Description :
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools. LDAP is a set of
protocols for accessing directory services (usually phone book style
information, but other information is possible) over the Internet,
similar to the way DNS (Domain Name System) information is propagated
over the Internet. The openldap package contains configuration files,
libraries, and documentation for OpenLDAP.

--------------------------------------------------------------------------------
Update Information:

fix rmw reference counting bug
new upstream release (#1059186); http://www.openldap.org/software/release/changes.html
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb  4 2014 Jan Synáček <jsynacek at redhat.com> - 2.4.39-2
- CVE-2013-4449: segfault on certain queries with rwm overlay (#1060851)
* Wed Jan 29 2014 Jan Synáček <jsynacek at redhat.com> - 2.4.39-1
- new upstream release (#1059186)
* Mon Nov 18 2013 Jan Synáček <jsynacek at redhat.com> - 2.4.38-1
- new upstream release (#1031608)
* Mon Nov 11 2013 Jan Synáček <jsynacek at redhat.com> - 2.4.37-2
- fix: slaptest incorrectly handles 'include' directives containing a custom file (#1028935)
* Wed Oct 30 2013 Jan Synáček <jsynacek at redhat.com> - 2.4.37-1
- new upstream release (#1023916)
- fix: missing a linefeed at the end of file /etc/openldap/ldap.conf (#1019836)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1019490 - CVE-2013-4449 openldap: segfault on certain queries with rwm overlay
        https://bugzilla.redhat.com/show_bug.cgi?id=1019490
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update openldap' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list