Bug#572005: [Pkg-openldap-devel] Bug#572005: openldap: CVE-2009-2408 certificate spoofing via null characters

2010-02-28 Thread Quanah Gibson-Mount
--On Sunday, February 28, 2010 4:09 PM -0500 Michael Gilbert wrote: Package: openldap Version: 2.4.17-2.1 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for openldap. The Debian build links against GnuTLS, not MozNSS, so it isn

Bug#572005: openldap: CVE-2009-2408 certificate spoofing via null characters

2010-02-28 Thread Michael Gilbert
Package: openldap Version: 2.4.17-2.1 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for openldap. CVE-2009-2408[0]: | Mozilla Network Security Services (NSS) before 3.12.3, Firefox before | 3.0.13, Thunderbird before 2.0.0.23, and S