krb5 1.12.1+dfsg-10ubuntu0.1 source package in Ubuntu

Changelog

krb5 (1.12.1+dfsg-10ubuntu0.1) utopic-security; urgency=medium

  * SECURITY UPDATE: use-after-free and double-free memory access
    violations
    - debian/patches/CVE-2014-5352.patch: properly handle context deletion
      in src/lib/gssapi/krb5/context_time.c,
      src/lib/gssapi/krb5/export_sec_context.c,
      src/lib/gssapi/krb5/gssapiP_krb5.h,
      src/lib/gssapi/krb5/gssapi_krb5.c,
      src/lib/gssapi/krb5/inq_context.c,
      src/lib/gssapi/krb5/k5seal.c,
      src/lib/gssapi/krb5/k5sealiov.c,
      src/lib/gssapi/krb5/k5unseal.c,
      src/lib/gssapi/krb5/k5unsealiov.c,
      src/lib/gssapi/krb5/lucid_context.c,
      src/lib/gssapi/krb5/prf.c,
      src/lib/gssapi/krb5/process_context_token.c,
      src/lib/gssapi/krb5/wrap_size_limit.c.
    - CVE-2014-5352
  * SECURITY UPDATE: denial of service via LDAP query with no results
    - debian/patches/CVE-2014-5353.patch: properly handle policy name in
      src/plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c.
    - CVE-2014-5353
  * SECURITY UPDATE: denial of service via database entry for a keyless
    principal
    - debian/patches/CVE-2014-5354.patch: support keyless principals in
      src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
    - CVE-2014-5354
  * SECURITY UPDATE: denial of service or code execution in kadmind XDR
    data processing
    - debian/patches/CVE-2014-9421.patch: fix double free in
      src/lib/kadm5/kadm_rpc_xdr.c, src/lib/rpc/auth_gssapi_misc.c.
    - CVE-2014-9421
  * SECURITY UPDATE: impersonation attack via two-component server
    principals
    - debian/patches/CVE-2014-9422.patch: fix kadmind server validation in
      src/kadmin/server/kadm_rpc_svc.c.
    - CVE-2014-9422
  * SECURITY UPDATE: gssrpc data leakage
    - debian/patches/CVE-2014-9423.patch: fix leakage in
      src/lib/gssapi/mechglue/mglueP.h, src/lib/rpc/svc_auth_gss.c.
    - CVE-2014-9423
 -- Marc Deslauriers <email address hidden>   Fri, 06 Feb 2015 15:15:07 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Utopic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
krb5_1.12.1+dfsg.orig.tar.gz 11.2 MiB eb29959f1e9f8d71e7401f5809daefae067296eb5b0da1176366280a16bdd784
krb5_1.12.1+dfsg-10ubuntu0.1.debian.tar.xz 107.3 KiB f712867cf44c284b5b3a6ca78282a046205142116202d3b7612c8c4ce574dce1
krb5_1.12.1+dfsg-10ubuntu0.1.dsc 3.4 KiB 18acd2cf8fd39175d059afcd9afae7727f3b5ada6b659176348fe3af1952a4c4

View changes file

Binary packages built by this source

krb5-admin-server: No summary available for krb5-admin-server in ubuntu utopic.

No description available for krb5-admin-server in ubuntu utopic.

krb5-doc: No summary available for krb5-doc in ubuntu utopic.

No description available for krb5-doc in ubuntu utopic.

krb5-gss-samples: No summary available for krb5-gss-samples in ubuntu utopic.

No description available for krb5-gss-samples in ubuntu utopic.

krb5-kdc: No summary available for krb5-kdc in ubuntu utopic.

No description available for krb5-kdc in ubuntu utopic.

krb5-kdc-ldap: No summary available for krb5-kdc-ldap in ubuntu utopic.

No description available for krb5-kdc-ldap in ubuntu utopic.

krb5-locales: No summary available for krb5-locales in ubuntu utopic.

No description available for krb5-locales in ubuntu utopic.

krb5-multidev: No summary available for krb5-multidev in ubuntu utopic.

No description available for krb5-multidev in ubuntu utopic.

krb5-otp: No summary available for krb5-otp in ubuntu utopic.

No description available for krb5-otp in ubuntu utopic.

krb5-pkinit: No summary available for krb5-pkinit in ubuntu utopic.

No description available for krb5-pkinit in ubuntu utopic.

krb5-user: No summary available for krb5-user in ubuntu utopic.

No description available for krb5-user in ubuntu utopic.

libgssapi-krb5-2: No summary available for libgssapi-krb5-2 in ubuntu utopic.

No description available for libgssapi-krb5-2 in ubuntu utopic.

libgssrpc4: No summary available for libgssrpc4 in ubuntu utopic.

No description available for libgssrpc4 in ubuntu utopic.

libk5crypto3: No summary available for libk5crypto3 in ubuntu utopic.

No description available for libk5crypto3 in ubuntu utopic.

libkadm5clnt-mit9: No summary available for libkadm5clnt-mit9 in ubuntu utopic.

No description available for libkadm5clnt-mit9 in ubuntu utopic.

libkadm5srv-mit9: No summary available for libkadm5srv-mit9 in ubuntu utopic.

No description available for libkadm5srv-mit9 in ubuntu utopic.

libkdb5-7: No summary available for libkdb5-7 in ubuntu utopic.

No description available for libkdb5-7 in ubuntu utopic.

libkrad-dev: No summary available for libkrad-dev in ubuntu utopic.

No description available for libkrad-dev in ubuntu utopic.

libkrad0: No summary available for libkrad0 in ubuntu utopic.

No description available for libkrad0 in ubuntu utopic.

libkrb5-3: No summary available for libkrb5-3 in ubuntu utopic.

No description available for libkrb5-3 in ubuntu utopic.

libkrb5-dbg: No summary available for libkrb5-dbg in ubuntu utopic.

No description available for libkrb5-dbg in ubuntu utopic.

libkrb5-dev: No summary available for libkrb5-dev in ubuntu utopic.

No description available for libkrb5-dev in ubuntu utopic.

libkrb5support0: No summary available for libkrb5support0 in ubuntu utopic.

No description available for libkrb5support0 in ubuntu utopic.