Bug#1036995: openldap: CVE-2023-2953

Ryan Tandy ryan at nardis.ca
Thu Jun 1 00:34:31 BST 2023


Hi, thanks for the report. If I've understood the issue correctly 
(DoS/crash if malloc fails), it does not look too urgent.

Although the fixes look safe enough, I think we could wait until after 
bookworm is released, and fix this in unstable first and in a point 
release later. Does that sound OK to you?

thanks,
Ryan



More information about the Pkg-openldap-devel mailing list