Re: [PATCH 0/1] Update OpenLDAP, fixing CVE-2015-6908

2016-04-24 Thread Leo Famulari
On Thu, Apr 21, 2016 at 02:57:48PM -0400, Leo Famulari wrote: > There is a remote denial of service bug in OpenLDAP in version 2.4.42 > and earlier [0]. > > This patch updates OpenLDAP to the latest version. > > This change will require several hundred packages to be rebuilt. Should > it go on se

Re: [PATCH 0/1] Update OpenLDAP, fixing CVE-2015-6908

2016-04-23 Thread Leo Famulari
On Fri, Apr 22, 2016 at 11:28:20PM -0400, Mark H Weaver wrote: > Leo Famulari writes: > > There is a remote denial of service bug in OpenLDAP in version 2.4.42 > > and earlier [0]. > > I think we'll need to graft this. Would you like to try grafting it on > your own system, see if anything obvio

Re: [PATCH 0/1] Update OpenLDAP, fixing CVE-2015-6908

2016-04-23 Thread Leo Famulari
On Fri, Apr 22, 2016 at 11:28:20PM -0400, Mark H Weaver wrote: > Leo Famulari writes: > > > There is a remote denial of service bug in OpenLDAP in version 2.4.42 > > and earlier [0]. > > I think we'll need to graft this. Would you like to try grafting it on > your own system, see if anything ob

Re: [PATCH 0/1] Update OpenLDAP, fixing CVE-2015-6908

2016-04-22 Thread Mark H Weaver
Leo Famulari writes: > There is a remote denial of service bug in OpenLDAP in version 2.4.42 > and earlier [0]. > > This patch updates OpenLDAP to the latest version. > > This change will require several hundred packages to be rebuilt. Should > it go on security-updates? Your advice requested...

[PATCH 0/1] Update OpenLDAP, fixing CVE-2015-6908

2016-04-21 Thread Leo Famulari
There is a remote denial of service bug in OpenLDAP in version 2.4.42 and earlier [0]. This patch updates OpenLDAP to the latest version. This change will require several hundred packages to be rebuilt. Should it go on security-updates? Your advice requested... [0] https://cve.mitre.org/cgi-bin/