File _patchinfo of Package patchinfo.4540

<patchinfo incident="4540">
  <issue id="904028" tracker="bnc">openldap2 %post requires binutils</issue>
  <issue id="937766" tracker="bnc">VUL-0: openldap2: The Logjam Attack / weakdh.org</issue>
  <issue id="945582" tracker="bnc">VUL-0: CVE-2015-6908: openldap2: ber_get_next remote denial of service vulnerability</issue>
  <issue id="955210" tracker="bnc">getaddrinfo does not return if ldap is used for host lookups in IPv6 environment</issue>
  <issue id="CVE-2015-4000" tracker="cve" />
  <issue id="CVE-2015-6908" tracker="cve" />
  <packager>guohouzuo</packager>
  <category>security</category>
  <rating>important</rating>
  <summary>Security update for openldap2</summary>
  <description>This update fixes the following security issues:

- CVE-2015-6908: The ber_get_next function allowed remote attackers to cause a denial
  of service (reachable assertion and application crash) via crafted BER data, as
  demonstrated by an attack against slapd. (bsc#945582)
- CVE-2015-4000: Fix weak Diffie-Hellman size vulnerability. (bsc#937766)

It also fixes the following non-security bugs:

- bsc#955210: Unresponsive LDAP host lookups in IPv6 environment
- bsc#904028: Add missing dependency binutils used by %pre.
</description>
</patchinfo>
openSUSE Build Service is sponsored by