openldap-2.4.40-8.el7
エラータID: AXSA:2015-705:02
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
Protocol) applications and development tools. LDAP is a set of
protocols for accessing directory services (usually phone book style
information, but other information is possible) over the Internet,
similar to the way DNS (Domain Name System) information is propagated
over the Internet. The openldap package contains configuration files,
libraries, and documentation for OpenLDAP.
Security issues fixed with this release:
CVE-2015-3276
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
Fixed bugs:
* The ORDERING matching rules have been added to the ppolicy attribute type descriptions. * The server no longer terminates unexpectedly when processing SRV records. * Missing objectClass information has been added, which enables the user to modify the front-end configuration by standard means.
Fixed bugs:
* Previously, OpenLDAP did not properly handle a number of simultaneous updates. As a consequence, sending a number of parallel update requests to the server could cause a deadlock. With this update, a superfluous locking mechanism causing the deadlock has been removed, thus fixing the bug.
* The httpd service sometimes terminated unexpectedly with a segmentation fault on the libldap library unload. The underlying source code has been modified to prevent a bad memory access error that caused the bug to occur. As a result, httpd no longer crashes in this situation.
* After upgrading the system from Red Hat Enterprise Linux 6 to Red Hat Enterprise Linux 7, symbolic links to certain libraries unexpectedly pointed to locations belonging to the openldap-devel package. If the user uninstalled openldap-devel, the symbolic links were broken and the "rpm -V openldap" command sometimes produced errors. With this update, the symbolic links no longer get broken in the described situation. If the user downgrades openldap to version 2.4.39-6 or earlier, the symbolic links might break. After such downgrade, it is recommended to verify that the symbolic links did not break. To do this, make sure the yum-plugin-verify package is installed and obtain the target libraries by running the "rpm -V openldap" or "yum verify openldap" command.
Enhancements:
* OpenLDAP clients now automatically choose the Network Security Services (NSS) default cipher suites for communication with the server. It is no longer necessary to maintain the default cipher suites manually in the OpenLDAP source code.
Update packages.
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
N/A
SRPMS
- openldap-2.4.40-8.el7.src.rpm
MD5: 99e545956f2091f4f44d95104bc841d9
SHA-256: a562907e804f48d7d4876e97ade01c823d89b26d8eda653661288dd5fa109f02
Size: 5.47 MB
Asianux Server 7 for x86_64
- openldap-2.4.40-8.el7.x86_64.rpm
MD5: 90c7d323ab757e0ac9a15e53edcee69b
SHA-256: 44adb88974d410a4b886dbf18f41496bbdc411c91ceecabaddca7c93b13cc9a1
Size: 347.04 kB - openldap-clients-2.4.40-8.el7.x86_64.rpm
MD5: f33bb8854f73723d3049e11d11058fa4
SHA-256: 37415d280304da406207c33bb1d8383dc21ab24af9f30f259e7c644fc3be9ae6
Size: 185.01 kB - openldap-devel-2.4.40-8.el7.x86_64.rpm
MD5: c59390830fa4c24e1c2e958ebeaca28c
SHA-256: 0649fa270844a4073a2a922a9ee0b4736dc92574f0f96346f110f0f7384ac0aa
Size: 798.21 kB - openldap-servers-2.4.40-8.el7.x86_64.rpm
MD5: 050c309ed3aeb13ef00ab71b0b206864
SHA-256: ef9d82cb00ccbfd1e4f69b89124703725c65ce8aba5fbb20089a2271dd715a86
Size: 2.11 MB - openldap-2.4.40-8.el7.i686.rpm
MD5: 74e6af962b96e46616455e31e32242f9
SHA-256: e58efaa975217fe4fd943bc7b39747b9d4f929a8f7f1dc33e85b7148f208ec59
Size: 344.66 kB - openldap-devel-2.4.40-8.el7.i686.rpm
MD5: 39a80c8551d8e437381a21ae1012bdf3
SHA-256: 0c24d227a6519009eb2993c28b61a6d3d5bade882814e400ce81e2cd46fd4404
Size: 798.21 kB