Debian: CVE-2022-29155: openldap: OpenLDAP SQL injection

Bug #1982723 reported by Zhixiong Chi
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
High
Zhixiong Chi

Bug Description

Brief Description
-----------------
Now the CVE-2022-29155 affects the starlingx debian project, the openldap package version is
2.4.57+dfsg-3

Severity
--------
Major

Steps to Reproduce
------------------
N/A

Expected Behavior
------------------
The version of openldap is up to 2.4.57+dfsg-3+deb11u1.

Actual Behavior
----------------
The version of openldap now is 2.4.57+dfsg-3.

Reproducibility
---------------
100%

System Configuration
--------------------
ALL debian starlingx node.

Branch/Pull Time/Commit
-----------------------
master

Last Pass
---------
N/A

Timestamp/Logs
--------------
N/A

Test Activity
-------------
N/A

Workaround
----------
N/A

CVE References

Changed in starlingx:
assignee: nobody → Zhixiong Chi (zhixiongchi)
status: New → In Progress
tags: added: stx.security
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to integ (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/integ/+/850854

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to integ (master)

Reviewed: https://review.opendev.org/c/starlingx/integ/+/850854
Committed: https://opendev.org/starlingx/integ/commit/e1f6fe0d569b53a5ad06c5af4a626c9fe6895cb1
Submitter: "Zuul (22348)"
Branch: master

commit e1f6fe0d569b53a5ad06c5af4a626c9fe6895cb1
Author: Zhixiong Chi <email address hidden>
Date: Sun Jul 24 22:26:32 2022 -0700

    Debian: openldap: fix CVE-2022-29155

    Upgrade the openldap version to 2.4.57+dfsg-3+deb11u1 to fix the
    CVE-2022-29155 issue.

    References:
    https://security-tracker.debian.org/tracker/CVE-2022-29155

    TestPlan:
    PASS: build-pkgs -c -p openldap
    PASS: build-image --std

    Closes-Bug: 1982723

    Signed-off-by: Zhixiong Chi <email address hidden>
    Change-Id: I1ac30da3e4597035ef4f816ca7ab95aa9adcaa7c

Changed in starlingx:
status: In Progress → Fix Released
Ghada Khalil (gkhalil)
tags: added: stx.8.0
Changed in starlingx:
importance: Undecided → High
tags: added: stx.debian
summary: - openldap: CVE-2022-29155
+ Debian: CVE-2022-29155: openldap: OpenLDAP SQL injection
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.