{"id":"SUSE-SU-2022:3286-1","summary":"Security update for 389-ds","details":"This update for 389-ds fixes the following issues:\n\n- CVE-2022-2850: Fixed an application crash when running a sync_repl client that could be triggered via a malformed cookie (bsc#1202470).\n\nNon-security fixes:\n\n- Update to version 2.0.16~git20.219f047ae:\n  * Fix missing 'not' in description\n  * CI - makes replication/acceptance_test.py::test_modify_entry more robust\n  * fix repl keep alive event interval\n  * Sync_repl may crash while managing invalid cookie\n  * Hostname when set to localhost causing failures in other tests\n  * lib389 - do not set backend name to lowercase\n  * keep alive update event starts too soon\n  * Fix various memory leaks\n  * UI - LDAP Editor is not updated when we switch instances\n  * Supplier should do periodic updates\n- Update sudoers schema to support UTF-8 (bsc#1197998)\n- Update to version 2.0.16~git9.e2a858a86:\n  * UI - Various fixes and RFE's for UI\n  * Remove problematic language from source code\n  * CI - disable TLS hostname checking\n  * Update npm and cargo packages\n  * Support ECDSA private keys for TLS\n","modified":"2026-03-11T07:21:02.667511Z","published":"2022-09-16T07:08:59Z","related":["CVE-2022-2850"],"upstream":["CVE-2022-2850"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223286-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2850"}],"affected":[{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP4","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.16~git20.219f047ae-150400.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"389-ds":"2.0.16~git20.219f047ae-150400.3.10.1","lib389":"2.0.16~git20.219f047ae-150400.3.10.1","libsvrcore0":"2.0.16~git20.219f047ae-150400.3.10.1","389-ds-devel":"2.0.16~git20.219f047ae-150400.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3286-1.json"}},{"package":{"name":"389-ds","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/389-ds&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.16~git20.219f047ae-150400.3.10.1"}]}],"ecosystem_specific":{"binaries":[{"lib389":"2.0.16~git20.219f047ae-150400.3.10.1","libsvrcore0":"2.0.16~git20.219f047ae-150400.3.10.1","389-ds-devel":"2.0.16~git20.219f047ae-150400.3.10.1","389-ds-snmp":"2.0.16~git20.219f047ae-150400.3.10.1","389-ds":"2.0.16~git20.219f047ae-150400.3.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3286-1.json"}}],"schema_version":"1.7.5"}