Bug#1036995: openldap: CVE-2023-2953

2023-05-31 Thread Salvatore Bonaccorso
Hi Ryan, On Wed, May 31, 2023 at 04:34:31PM -0700, Ryan Tandy wrote: > Hi, thanks for the report. If I've understood the issue correctly (DoS/crash > if malloc fails), it does not look too urgent. Correct, agreed. > Although the fixes look safe enough, I think we could wait until after > bookwor

Bug#1036995: openldap: CVE-2023-2953

2023-05-31 Thread Ryan Tandy
Hi, thanks for the report. If I've understood the issue correctly (DoS/crash if malloc fails), it does not look too urgent. Although the fixes look safe enough, I think we could wait until after bookworm is released, and fix this in unstable first and in a point release later. Does that sound

Bug#1036995: openldap: CVE-2023-2953

2023-05-31 Thread Salvatore Bonaccorso
Source: openldap Version: 2.5.13+dfsg-5 Severity: important Tags: security upstream Forwarded: https://bugs.openldap.org/show_bug.cgi?id=9904 X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: fixed -1 2.6.4+dfsg-1~exp1 Hi, The following vulnerability was published for openldap. CVE