CVE-2025-59518:
(postponed; to be fixed through a stable update)
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.
1 new commit since last upload, is it time to release?
normal
vcswatch reports that
this package seems to have new commits in its VCS but has
not yet updated debian/changelog. You should consider updating
the Debian changelog and uploading this new version into the archive.
Here are the relevant commit logs:
commit 6f4b42ea5eb78d14c63b30ee97ef5220b0611375
Author: Yadd <yadd@debian.org>
Date: Sun May 17 16:51:56 2026 +0200
Add copyright of test files