diff options
| author | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-01-13 07:35:45 +0100 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-01-20 18:22:05 +0100 |
| commit | 6d0101825091319d4dc13e50b386b68dd6d06453 (patch) | |
| tree | 823b9dd68daea272db49c0a3f7a1a55009b36d99 /meta-networking/recipes-devtools/python/python3-ldap | |
| parent | 3a9a13832b9d8ce4c61b11c643b1dae07f1743f7 (diff) | |
| download | meta-openembedded-6d0101825091319d4dc13e50b386b68dd6d06453.tar.gz | |
python3-ldap: patch CVE-2025-61912
Details: https://nvd.nist.gov/vuln/detail/CVE-2025-61912
Pick the patch that's mentioned by the NVD advisory.
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-networking/recipes-devtools/python/python3-ldap')
| -rw-r--r-- | meta-networking/recipes-devtools/python/python3-ldap/CVE-2025-61912.patch | 42 |
1 files changed, 42 insertions, 0 deletions
diff --git a/meta-networking/recipes-devtools/python/python3-ldap/CVE-2025-61912.patch b/meta-networking/recipes-devtools/python/python3-ldap/CVE-2025-61912.patch new file mode 100644 index 0000000000..1e3940e662 --- /dev/null +++ b/meta-networking/recipes-devtools/python/python3-ldap/CVE-2025-61912.patch | |||
| @@ -0,0 +1,42 @@ | |||
| 1 | From b80ba3e3b41859bfc79830b726e95e457502ca00 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Simon Pichugin <simon.pichugin@gmail.com> | ||
| 3 | Date: Fri, 10 Oct 2025 10:46:45 -0700 | ||
| 4 | Subject: [PATCH] Merge commit from fork | ||
| 5 | |||
| 6 | Update tests to expect \00 and verify RFC-compliant escaping | ||
| 7 | |||
| 8 | CVE: CVE-2025-61912 | ||
| 9 | Upstream-Status: Backport [https://github.com/python-ldap/python-ldap/commit/6ea80326a34ee6093219628d7690bced50c49a3f] | ||
| 10 | Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> | ||
| 11 | --- | ||
| 12 | Lib/ldap/dn.py | 3 ++- | ||
| 13 | Tests/t_ldap_dn.py | 2 +- | ||
| 14 | 2 files changed, 3 insertions(+), 2 deletions(-) | ||
| 15 | |||
| 16 | diff --git a/Lib/ldap/dn.py b/Lib/ldap/dn.py | ||
| 17 | index a9d9684..8d40673 100644 | ||
| 18 | --- a/Lib/ldap/dn.py | ||
| 19 | +++ b/Lib/ldap/dn.py | ||
| 20 | @@ -26,7 +26,8 @@ def escape_dn_chars(s): | ||
| 21 | s = s.replace('>' ,'\\>') | ||
| 22 | s = s.replace(';' ,'\\;') | ||
| 23 | s = s.replace('=' ,'\\=') | ||
| 24 | - s = s.replace('\000' ,'\\\000') | ||
| 25 | + # RFC 4514 requires NULL (U+0000) to be escaped as hex pair "\00" | ||
| 26 | + s = s.replace('\x00' ,'\\00') | ||
| 27 | if s[-1]==' ': | ||
| 28 | s = ''.join((s[:-1],'\\ ')) | ||
| 29 | if s[0]=='#' or s[0]==' ': | ||
| 30 | diff --git a/Tests/t_ldap_dn.py b/Tests/t_ldap_dn.py | ||
| 31 | index 86d3640..7c04777 100644 | ||
| 32 | --- a/Tests/t_ldap_dn.py | ||
| 33 | +++ b/Tests/t_ldap_dn.py | ||
| 34 | @@ -49,7 +49,7 @@ class TestDN(unittest.TestCase): | ||
| 35 | self.assertEqual(ldap.dn.escape_dn_chars(' '), '\\ ') | ||
| 36 | self.assertEqual(ldap.dn.escape_dn_chars(' '), '\\ \\ ') | ||
| 37 | self.assertEqual(ldap.dn.escape_dn_chars('foobar '), 'foobar\\ ') | ||
| 38 | - self.assertEqual(ldap.dn.escape_dn_chars('f+o>o,b<a;r="\00"'), 'f\\+o\\>o\\,b\\<a\\;r\\=\\"\\\x00\\"') | ||
| 39 | + self.assertEqual(ldap.dn.escape_dn_chars('f+o>o,b<a;r="\00"'), r'f\+o\>o\,b\<a\;r\=\"\00\"') | ||
| 40 | self.assertEqual(ldap.dn.escape_dn_chars('foo\\,bar'), 'foo\\\\\\,bar') | ||
| 41 | |||
| 42 | def test_str2dn(self): | ||
