On 21.11.2013 17:38, Salvatore Bonaccorso wrote:
> Package: 389-ds-base
> Severity: grave
> Tags: security upstream
> 
> Hi Timo,
> 
> the following vulnerability was published for ds-base.
> 
> CVE-2013-4485[0]:
> DoS due to improper handling of ger attr searches
> 
> See Red Hat bugzilla entry for the patch and details.
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

This, and the four other open CVE's are fixed in git by v1.3.2.8.

trying to find a sponsor for it to get these finally fixed.

-- 
t


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to