[Pkg-openldap-devel] Bug#515232: Bug#515232: slapd: segfaults with seemingly valid unique_overlay construct

Quanah Gibson-Mount quanah at zimbra.com
Sun Feb 15 03:37:04 UTC 2009


--On Sunday, February 15, 2009 3:18 AM +0000 Stephen Gran 
<sgran at debian.org> wrote:

> Package: slapd
> Version: 2.4.11-1
> Severity: important
>
> Hello all,
>
> I have the following in slapd.conf:
>
> overlay         unique
>
> unique_uri      ldap:///?mail?sub?
> unique_uri      ldap:///ou=People,dc=lobefin,dc=net?uidNumber,uid?sub
>
> Based on this in the manpage:
>
>   The LDAP URI syntax is a subset of RFC-4516, and takes the form:
>     ldap:///[base dn]?[attributes...]?scope[?filter]
>
> Starting slapd with this line causes a segfault, sadly.

You need to upgrade.

Honestly I'd suggest someone backport 2.4.14, as it fixed numerous bits 
with GnuTLS as well.

However, 2.4.12 and later only link against BDB 4.4 or later, of which I'd 
suggest BDB 4.7.25 + all 3 patches from Oracle.

OpenLDAP 2.4.12 Release (2008/10/12)
	Fixed slapo-unique filter validation (ITS#5581)
	Fixed slapo-unique suffix testing (ITS#5641)


OpenLDAP 2.4.14 Release (2009/02/14)
	Added libldap TLS_PROTOCOL_MIN (ITS#5655)
	Added libldap GnuTLS support for TLS_CIPHER_SUITE (ITS#5887)
	Added libldap GnuTLS setting random file (ITS#5462)


for example.

--Quanah

--

Quanah Gibson-Mount
Principal Software Engineer
Zimbra, Inc
--------------------
Zimbra ::  the leader in open source messaging and collaboration





More information about the Pkg-openldap-devel mailing list