Bug#729367: Re: openldap: CVE-2013-4449

2014-04-08 Thread Ryan Tandy
tags 729367 + pending thanks Reproduced in openldap 2.4.39-1 using Jan Synacek's test case: http://jsynacek.fedorapeople.org/openldap/its7723/reproducer/ Verified that this patch fixes the bug, committed to git. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subje

Bug#729367: Re: openldap: CVE-2013-4449

2014-04-05 Thread Ryan Tandy
On 22/02/14 08:10 AM, Hideki Yamane wrote: I've taken the patch from RHEL for this issue, and can build it. Upstream doesn't apply it yet, I'm not sure why, but it's worth to check, IMO. Upstream have applied the patch recently to their 2.4 and 2.5 branches. http://www.openldap.org/devel