-
-
25.0.2+10
-
25.0.2+10
-
25.0.2+10
-
CVE-2019-13565
OL CVE Issue Summary:
When usingSASLauthentication and session encryption, and relying on the security layers inslapdaccess controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in thoseACLs. After the firstSASLbind is completed, thesasl_ssfvalue is retained for all new non-SASL connections. Depending on theACLconfiguration, this can affect different types of operations (searches, modifications, etc.).
In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.CVE-2019-13565openldap-2.4.44-25_ol002.el7_97.5 -
CVE-2025-49794
OL CVE Issue Summary:
A Heap Use After Free vulnerability was discovered inSchematron. The issue arises in thexmlSchematronGetNode()when processingXPathexpressions inSchematronschema elements<sch:name path="..."/>, where a pointer to freed memory is returned and then accessed, leading to undefined behavior and potential crashes.Vulnerable component:
xmlSchematronGetNode()extracts a pointer to a node from anXPathnode set and then immediately frees the entireXPathobject containing that node set, rendering the returned pointer invalid.CVE-2025-49794libxml2-2.9.1-6_ol005.el7.6libxml29.1 -
CVE-2025-47273
OL CVE Issue Summary :
setuptoolsis a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability inPackageIndexis present in setuptools prior to version 78.1.1.
An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.
CVE-2025-47273python3-setuptools-39.2.0-10_ol002.el7python37.7 -
CVE-2015-8853
OL CVE Issue Summary:
S_reghop3(),S_reghop4(), andS_reghopmaybe3()inregexec.c(before 5.24.0) allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated with the payload `"a\x80"`.CVE-2015-8853perl-5.16.3-299_ol004.el77.5 -
CVE-2025-32415
OL CVE Issue Summary:
xmlSchemaIDCFillNodeTables()inxmlschemas.chas a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
CVE-2025-32415libxml2-2.9.1-6_ol006.el7.6libxml2-2.9.1-6_ol006.el7.6 (392)7.5 -
CVE-2017-7500
OL CVE Issue Summary:
rpmdid not properly handle installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination.
An attacker with write access to a directory in which a subdirectory will be installed could redirect that directory to an arbitrary location and gain superuser privileges.CVE-2017-7500rpm-4.11.3-48_ol001.el77.8