{"affected":[{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Legacy 12","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7","libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7","libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"openldap2-client","purl":"pkg:rpm/suse/openldap2-client&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7","libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7","libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"openldap2-client","purl":"pkg:rpm/suse/openldap2-client&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"compat-libldap-2_3-0":"2.3.37-18.24.9.7"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"openldap2-client","purl":"pkg:rpm/suse/openldap2-client&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1-LTSS","name":"openldap2","purl":"pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.7"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libldap-2_4-2":"2.4.41-18.24.9.1","libldap-2_4-2-32bit":"2.4.41-18.24.9.1","openldap2":"2.4.41-18.24.9.7","openldap2-back-meta":"2.4.41-18.24.9.7","openldap2-client":"2.4.41-18.24.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1-LTSS","name":"openldap2-client","purl":"pkg:rpm/suse/openldap2-client&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.41-18.24.9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for openldap2 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-9287: A double free vulnerability in the mdb backend during search with page size 0 was fixed (bsc#1041764).\n- CVE-2017-17740: Fixed a denial of service (slapd crash) via a member MODDN operation that could have been triggered when both the nops module and the memberof overlay are enabled (bsc#1073313).\n\nNon-security issues fixed:\n\n- Fix a regression in handling of non-blocking connections (bsc#1031702)\n- Fix an uninitialised variable that causes startup failure (bsc#1037396)\n- Fix libldap leaks socket descriptors issue (bsc#1065083)\n","id":"SUSE-SU-2019:0931-1","modified":"2019-04-11T09:11:33Z","published":"2019-04-11T09:11:33Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20190931-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031702"},{"type":"REPORT","url":"https://bugzilla.suse.com/1037396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1041764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1065083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1073313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-17740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9287"}],"related":["CVE-2017-17740","CVE-2017-9287"],"summary":"Security update for openldap2","upstream":["CVE-2017-17740","CVE-2017-9287"]}