This update for 389-ds fixes the following issues:
Update to version 2.2.10~git255.752643c78.
Security issues fixed:
sasl_io_recv() can lead to a heap buffer overflow when processing a
specially crafted oversized LDAP UNBIND packet (bsc#1270695).sasl_io_start_packet() can lead to heap buffer overflow when processing a
crafted SASL packet length prefix (bsc#1268298).ldap_utf8prev() functioncan can lead to a heap buffer overread in
string filter parsing(bsc#1268062).ns-slapd crash when concurrent LDAP
query traffic is active (bsc#1268047).create_masked_entry_string can lead to a heap and log output corruption whe a
short cleartext password is logged (bsc#1268046).checkPrefix() can lead to a stack buffer overflow when processing an
algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041).__aclp__normalize_acltxt() function can lead to heap buffer overflow
when processing a malformed ACI string (bsc#1268491).Other updates and bugfixes:
ldap-agent SNMP stats file loading (#7630)checkPrefix389-ds-base Audit Log Password Maskingget_pid to fix check_asan_report (#7625)lib389 user compare fails due to parentid mismatch (#7603)sasl_io_start_packet (#7594)npm - ws, js-yaml, js-yaml , postcss, uuid__aclp__normalize_acltxt() (#7542)lib389 - Add helper function for checking ASAN filesnsSubStrBegin/nsSubStrEnd values (#7550)nsSubStrBegin/nsSubStrEnd
lengths are configured (#7441)LeakSanitizer: memory leaks in CoS cache error paths (#7438)AddressSanitizer: leaks found by acl test suitenpm - brace-expansion (#7556)ber_init failsdblayer_bulk_nextdata should not return an error when maxrecords is hit