Package: libnss-ldapd
Version: 0.9.4-3
Severity: important
Tags: ipv6

Dear Maintainer,

The version 0.9.4 of libnss-ldapd contains a flaw that makes the
`getent hosts` command and similar name resolution crash when the LDAP
directory contains mixed IPv4 and IPv6 ipHostNumbers.

I discussed this issue with upstream on
http://lists.arthurdejong.org/nss-pam-ldapd-users/2016/msg00005.html
and it is fixed in 0.9.6. I would recommend that Debian provide an
update to stable for this package.

To reproduce: create a Host with both an IPv4 and IPv6 ipHostNumber
assigned inm your directory. NSSWITCH should contain `ldap` in the
hosts section. Then you can observe the crash with either `getent
hosts hostname` or simply `getent hosts`.

This issue severely affects our LDAP based hosts lists since we
started to deploy dual IPv4/IPv6 VMs.

Thanks,


-- System Information:
Debian Release: 8.2
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.16.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=zh_CN.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libnss-ldapd depends on:
ii  debconf [debconf-2.0]  1.5.56
ii  libc6                  2.19-18+deb8u1
ii  multiarch-support      2.19-18+deb8u1
ii  nslcd [nslcd-2]        0.9.4-3

libnss-ldapd recommends no packages.

libnss-ldapd suggests no packages.

-- debconf information:
  libnss-ldapd/clean_nsswitch: false
* libnss-ldapd/nsswitch: passwd, group, hosts, automount

Reply via email to