[Date Prev][Date Next]
liblber makefile regresses other libraries (ITS#2798)
Full_Name: Joseph S D Yao
OS: Linux - Red Hat 8.0 w/ patches and Bastille
Submission from: (NULL) (188.8.131.52)
This is a security issue, as it regresses previously installed libraries with
fixes back to the less secure forms.
Starting with Red Hat Linux 8.0, after adding patches and Bastille Linux, I
installed OpenSSL 0.9.7c, OpenLDAP 2.1.22, and Sendmail 8.12.10. When I got to
'sendmail', it declared that some of the libraries in the previous packages were
It turns out that, while installing OpenLDAP, the liblber Makefile calls
'libtool', which calls 'ldconfig'. The new OpenLDAP library is NOT entered into
the library configuration by 'ldconfig'. But the symbolic links in /usr/lib to
libssl.so.0.9.7 and libcrypto.so.0.9.7 have been removed, and replaced by
symbolic links to the original 0.9.5a files.
How to fix?