https://bugs.openldap.org/show_bug.cgi?id=9370
--- Comment #4 from Howard Chu <hyc(a)openldap.org> ---
(In reply to Salvatore Bonaccorso from comment #3)
> CVE-2020-25692 was assigned for this issue.
Fyi, the official OpenLDAP Project policy is that only unintended information
disclosures count as security issues, and this item does not qualify.
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=9370
--- Comment #3 from Salvatore Bonaccorso <carnil(a)debian.org> ---
CVE-2020-25692 was assigned for this issue.
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=9383
Howard Chu <hyc(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Group|OpenLDAP-devs |
--- Comment #2 from Howard Chu <hyc(a)openldap.org> ---
(In reply to phasip from comment #0)
> A malicious packet can force OpenLDAP to fail an assertion and crash.
> slapd: schema_init.c:419: int certificateListValidate(Syntax *, struct
> berval *): Assertion `tag == LBER_INTEGER' failed.
Note that this code was behind #ifdef LDAP_DEVEL so it is not vulnerable
in any public OpenLDAP releases.
--
You are receiving this mail because:
You are on the CC list for the issue.