From b0077fc1af912cd733a148bd52565409b522fb55917715122c78e2b9bc9dcd56 Mon Sep 17 00:00:00 2001 From: Samuel Cabrero Date: Wed, 24 Mar 2021 14:50:43 +0000 Subject: [PATCH] Accepting request 881035 from home:npower:branches:network:samba:STABLE - Release ldb 2.2.1 + CVE-2020-27840: samba: Unauthenticated remote heap corruption via bad DNs; (bso#14595); (bsc#1183572). + CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; (bso#14655); (bsc#1183574). OBS-URL: https://build.opensuse.org/request/show/881035 OBS-URL: https://build.opensuse.org/package/show/network:samba:STABLE/ldb?expand=0&rev=157 --- ldb-2.2.0.tar.asc | 11 ----------- ldb-2.2.0.tar.gz | 3 --- ldb-2.2.1.tar.asc | 11 +++++++++++ ldb-2.2.1.tar.gz | 3 +++ ldb.changes | 9 +++++++++ ldb.spec | 4 ++-- 6 files changed, 25 insertions(+), 16 deletions(-) delete mode 100644 ldb-2.2.0.tar.asc delete mode 100644 ldb-2.2.0.tar.gz create mode 100644 ldb-2.2.1.tar.asc create mode 100644 ldb-2.2.1.tar.gz diff --git a/ldb-2.2.0.tar.asc b/ldb-2.2.0.tar.asc deleted file mode 100644 index e2f28ff..0000000 --- a/ldb-2.2.0.tar.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQFJBAABCgAzFiEEkUejOXGVGO6QEby1R5ORYRMIQCUFAl8HCQwVHHNhbWJhLWJ1 -Z3NAc2FtYmEub3JnAAoJEEeTkWETCEAlrwkH/A/MJM5E0Pyz6HNdctHSrA97FB6Q -JI1MnsyXerZXfDulcUFmyrNPp66gLGeNGG2X9eoxvWrZk3hPnYe9YPE6UiwCKxZu -1CSp2JuwaVB6EoUxUIuh63DFlF9Th/ZEhPsBrP3tQHvZyGpTDOQq3qhV7FLsrIwO -RstK5CJIqmgwy84oJmKanWLWfTqdp/HBvVsZw0/kZ0Kr+3DUcM9MaY7hifMpcSOV -8HTMgIpEoPbKkNOMj2lkDiYcx3tLWtdMYQdN31Cng3X9n5XmLX0GQlfCjfediSkT -vK2RGlIp/hlEXOSyIG2mJync+u4NCOv7r8EEcVhjHDYOflIvfOiwbITtWMg= -=/f7o ------END PGP SIGNATURE----- diff --git a/ldb-2.2.0.tar.gz b/ldb-2.2.0.tar.gz deleted file mode 100644 index 849370f..0000000 --- a/ldb-2.2.0.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:134bb51769709af59f30bf468e454d1377a8096acd4e80dcb42fd264f558bd5f -size 1676551 diff --git a/ldb-2.2.1.tar.asc b/ldb-2.2.1.tar.asc new file mode 100644 index 0000000..9cda423 --- /dev/null +++ b/ldb-2.2.1.tar.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCgAdFiEEkUejOXGVGO6QEby1R5ORYRMIQCUFAmBbCkoACgkQR5ORYRMI +QCUQxwf/feTw7uyNrjCu8kuNm5sZHXFHYp4sQ5Ptm0Y+pu5+IOATYQPzfNPk0ut5 +uep+3kDCaXsiNcD+KrPE0LhJqhqVjhkeTqgSs8dIf81ZUQjSnC2Ehi0kvD5qDHZC +rNXwCad6lzfE6GCtST/cgSRIwRGayQro8Ulaet/HWFcMZXzT89BpJaHbTuQmOIdI +8MtaTj4ibQXFzfNeNZMG8pt+Ybi9crs0idfi0Q3p2IPXluX8pgenulpHnC+OA1n2 +pX2V2MoW8Qd845waJlfP8r0Wr50nKk4ZdpqWdfnP39jQnxdOxgUyqBleCDqVMijb +5HQxyz2sDvlfHlKR6dQYylY0xuy8zQ== +=MnEv +-----END PGP SIGNATURE----- diff --git a/ldb-2.2.1.tar.gz b/ldb-2.2.1.tar.gz new file mode 100644 index 0000000..e07b713 --- /dev/null +++ b/ldb-2.2.1.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f7eb8f6f399c7240a6f0fe8e591b6f51ccacbfc563c5f53d5a641a21aa7e9804 +size 1676819 diff --git a/ldb.changes b/ldb.changes index 4c90678..6238c46 100644 --- a/ldb.changes +++ b/ldb.changes @@ -1,3 +1,12 @@ +------------------------------------------------------------------- +Wed Mar 24 09:53:56 UTC 2021 - Noel Power + +- Release ldb 2.2.1 + + CVE-2020-27840: samba: Unauthenticated remote heap corruption + via bad DNs; (bso#14595); (bsc#1183572). + + CVE-2021-20277: samba: out of bounds read in ldb_handler_fold; + (bso#14655); (bsc#1183574). + ------------------------------------------------------------------- Mon Oct 12 15:28:18 UTC 2020 - Dominique Leuenberger diff --git a/ldb.spec b/ldb.spec index c2710b5..d70e906 100644 --- a/ldb.spec +++ b/ldb.spec @@ -1,7 +1,7 @@ # # spec file for package ldb # -# Copyright (c) 2020 SUSE LLC +# Copyright (c) 2021 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -57,7 +57,7 @@ BuildRequires: lmdb-devel >= %{lmdb_version} %endif URL: https://ldb.samba.org/ -Version: 2.2.0 +Version: 2.2.1 Release: 0 Summary: An LDAP-like embedded database License: LGPL-3.0-or-later