Bug 729087 - memleak - free the return of tlsm_find_and_verify_cert_key
Summary: memleak - free the return of tlsm_find_and_verify_cert_key
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: openldap
Version: 6.1
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Jan Vcelak
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On: 725818
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-08-08 17:13 UTC by Jan Vcelak
Modified: 2013-03-04 01:29 UTC (History)
6 users (show)

Fixed In Version: openldap-2.4.23-17.el6
Doc Type: Bug Fix
Doc Text:
- All tools using OpenLDAP library and using TLS to connect to the server, while the library fails to verify certificate or key. - Memory leak appears in tlsm_find_and_verify_cert_key. - The patch was applied to correctly dispose verified certificate or key when it's verification fails. - No more memory leaks when OpenLDAP library fails to verify a certificate or a key.
Clone Of: 725818
Environment:
Last Closed: 2011-12-06 11:49:34 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2011:1514 normal SHIPPED_LIVE openldap bug fix and enhancement update 2011-12-06 00:51:20 UTC

Description Jan Vcelak 2011-08-08 17:13:53 UTC
openldap-2.4.23-16.el6 is also affected

Rich's patch was already included upstream.

+++ This bug was initially created as a clone of Bug #725818 +++

Description of problem:

http://www.openldap.org/its/index.cgi?findid=7001

Comment 2 Jan Vcelak 2011-08-15 08:24:17 UTC
Resolved in openldap-2.4.23-17.el6

Comment 3 Jan Vcelak 2011-08-15 11:53:32 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
- All tools using OpenLDAP library and using TLS to connect to the server, while the library fails to verify certificate or key.
- Memory leak appears in tlsm_find_and_verify_cert_key.
- The patch was applied to correctly dispose verified certificate or key when it's verification fails.
- No more memory leaks when OpenLDAP library fails to verify a certificate or a key.

Comment 6 errata-xmlrpc 2011-12-06 11:49:34 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1514.html


Note You need to log in before you can comment on or make changes to this bug.