Debian Patches

Status for 389-ds-base/3.1.2+dfsg1-1

Patch Description Author Forwarded Bugs Origin Last update
fix-saslpath.diff no
use-packaged-rust-registry.diff no
allow-newer-crates.diff no
base64.diff update for base64 0.21 Peter Michael Green <plugwash@debian.org> no
0001-Security-fix-for-CVE-2025-2487.patch [PATCH] Security fix for CVE-2025-2487
Description:
A denial of service vulnerability was found in the 389 Directory Server.
The 389 Directory Server may crash (Null Pointer Exception) after some
failed rename subtree operations (i.e. MODDN) issued by a user having enough
privileges to do so.

References:
- https://access.redhat.com/security/cve/CVE-2025-2487
- https://bugzilla.redhat.com/show_bug.cgi?id=2353071
Pierre Rogier <progier@redhat.com> no 2025-02-27

All known versions for source package '389-ds-base'

Links