USN-2856-1: ldb vulnerabilities
Ubuntu Security Notice USN-2856-1 5th January, 2016 ldb vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in ldb. Software description ldb – LDAP-like embedded database Details Thilo Uttendorfer discovered that the ldb incorrectly handled certain zerovalues. A remote attacker could use this issue to cause applications usingldb, such as Samba, to stop responding, resulting in a denial of service.(CVE-2015-3223) Douglas Bagnall discovered that ldb incorrectly handled certain stringlengths. A remote attacker could use this issue to possibly accesssensitive information from memory of applications using ldb, such as Samba.(CVE-2015-5330) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: libldb1 2:1.1.20-2ubuntu0.1 Ubuntu 15.04: libldb1 1:1.1.18-1ubuntu0.1 Ubuntu 14.04 LTS: libldb1 1:1.1.16-1ubuntu0.1 Ubuntu 12.04 LTS: [ more… ]