Re: [Bug 423252] nss-ldap, SUID executables, gcrypt

2012-04-24 Thread Ansgar Burchardt
Thorsten Glaser <423...@bugs.launchpad.net> writes: > Why not do a readline and provide *two* versions of the > OpenLDAP client libraries, keep libldap-2.4-2 linked > against gnutls26 and add another shared library plus > development package (with at least the two shared library > packages coïnstal

[Bug 423252] nss-ldap, SUID executables, gcrypt

2012-04-24 Thread Thorsten Glaser
Hi all, this bug has been brought to my attention by my boss today. If I understand the situation correctly, the problem is: • OpenLDAP links against GnuTLS (gnutls26) • gnutls26 links against gcrypt, which has the bug • gnutls28 links against nettle, but also gmp which is LGPLv3+ • OpenLDAP thus