[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-17 Thread Launchpad Bug Tracker
This bug was fixed in the package openldap - 2.4.25-1.1ubuntu4.1 --- openldap (2.4.25-1.1ubuntu4.1) oneiric-security; urgency=low * SECURITY UPDATE: potential denial of service (LP: #884163) - debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize()

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-17 Thread Launchpad Bug Tracker
This bug was fixed in the package openldap - 2.4.23-6ubuntu6.1 --- openldap (2.4.23-6ubuntu6.1) natty-security; urgency=low * SECURITY UPDATE: potential denial of service (LP: #884163) - debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize() -

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-17 Thread Launchpad Bug Tracker
This bug was fixed in the package openldap - 2.4.23-0ubuntu3.7 --- openldap (2.4.23-0ubuntu3.7) maverick-security; urgency=low * SECURITY UPDATE: potential denial of service (LP: #884163) - debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize()

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-17 Thread Launchpad Bug Tracker
This bug was fixed in the package openldap - 2.4.21-0ubuntu5.6 --- openldap (2.4.21-0ubuntu5.6) lucid-security; urgency=low * SECURITY UPDATE: potential denial of service (LP: #884163) - debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize() -

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-14 Thread Jamie Strandboge
Hardy's openldap2.3 does not have postalAddressValidate(), which is the only known function to pass UTF8StringNormalize() a 0 length string. ** Changed in: openldap (Ubuntu Hardy) Status: In Progress = Invalid ** Changed in: openldap (Ubuntu Hardy) Assignee: Jamie Strandboge

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-14 Thread Jamie Strandboge
** Changed in: openldap (Ubuntu Lucid) Status: In Progress = Fix Committed ** Changed in: openldap (Ubuntu Maverick) Status: In Progress = Fix Committed ** Changed in: openldap (Ubuntu Natty) Status: In Progress = Fix Committed -- You received this bug notification because

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-14 Thread Jamie Strandboge
** Changed in: openldap (Ubuntu Precise) Status: In Progress = Fix Committed ** Changed in: openldap (Ubuntu Oneiric) Status: In Progress = Fix Committed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openldap in

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-14 Thread Launchpad Bug Tracker
This bug was fixed in the package openldap - 2.4.25-3ubuntu2 --- openldap (2.4.25-3ubuntu2) precise; urgency=low * SECURITY UPDATE: potential denial of service (LP: #884163) - debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize() -

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-07 Thread Jamie Strandboge
** Changed in: openldap (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openldap in Ubuntu. https://bugs.launchpad.net/bugs/884163 Title: OpenLDAP

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-07 Thread Jamie Strandboge
** Changed in: openldap (Ubuntu) Status: Confirmed = In Progress ** Also affects: openldap (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: openldap (Ubuntu Lucid) Importance: Undecided Status: New ** Also affects: openldap (Ubuntu Natty)

[Bug 884163] Re: OpenLDAP UTF8StringNormalize() Off-by-One Denial of Service Vulnerability

2011-11-06 Thread Marc Deslauriers
** Visibility changed to: Public ** Visibility changed to: Public ** Changed in: openldap (Ubuntu) Status: New = Confirmed ** Changed in: openldap (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is