Vulnerability Bulletins

DSA-4046 libspring-ldap-java - security update

   
Affected software Debian
 
Tobias Schneider discovered that libspring-ldap-java, a Java libraryfor Spring-based applications using the Lightweight Directory AccessProtocol, would under some circumstances allow authentication with acorrect username but an arbitrary password.

More info:

https://www.debian.org/security/2017/dsa-4046