package/openldap: add upstream security fix for CVE-2021-27212
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 26 Feb 2021 23:13:17 +0000 (00:13 +0100)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 27 Feb 2021 08:10:45 +0000 (09:10 +0100)
commit2d6a0ea93e8adf53377b6c1ab06e07ce1ba4961a
treee67da19fb05fde3aca9d069d27496c9ad4a502b0
parent6ca1a7c2773cc13f71e284d0b3b4b3b35101d1db
package/openldap: add upstream security fix for CVE-2021-27212

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion
failure in slapd can occur in the issuerAndThisUpdateCheck function via a
crafted packet, resulting in a denial of service (daemon exit) via a short
timestamp.  This is related to schema_init.c and checkTime.

For more details, see the bugtracker:
https://bugs.openldap.org/show_bug.cgi?id=9454

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/openldap/0005-ITS-9454-fix-issuerAndThisUpdateCheck.patch [new file with mode: 0644]
package/openldap/openldap.mk