Change logs for krb5 source package in Oneiric based series for Ubuntu LEB

  • krb5 (1.9.1+dfsg-1ubuntu1.1) oneiric-security; urgency=low
    
      * SECURITY UPDATE: fix multiple kdc DoS issues:
        - db2/lockout.c, ldap/libkdb_ldap/ldap_principal2.c,
          ldap/libkdb_ldap/lockout.c:
          + more strict checking for null pointers
          + disable assert iand return when db is locked
          + applied inline
        - CVE-2011-1527, CVE-2011-1528, and CVE-2011-1529
      *
     -- Steve Beattie <email address hidden>   Mon, 10 Oct 2011 11:11:47 -0700
  • krb5 (1.9.1+dfsg-1ubuntu1) oneiric; urgency=low
    
      * Merge from debian unstable.  Remaining changes:
        - Build for multiarch, with pre-depends on multi-arch support virtual package.
        - Add Breaks: on old versions fo external packages (i.e., ssd) using
          /usr/lib/krb5 due to the path tranisition
    
    krb5 (1.9.1+dfsg-1) unstable; urgency=low
    
      * New upstream version
      * Fix g_make_token_header when no token type is passed
      * Support absolute paths for GSS-API mechanisms
      * Add gss_authorize_localname, gss_userok,  gss_pname_to_uid
      * Fix gss_acquire_cred handling with empty mech set; fix
        accept_sec_context handling in this case too
      * Permit importing anonymous name with empty buffer
          * New Translations:
        - Dutch: Thanks  Vincent Zweije, Closes: #624173
        - Danish, Thanks  Joe Dalton, Closes: #626530
      * Fix kadmin free of null pointer on change password, Closes: #622681
    
    krb5 (1.9+dfsg-2) unstable; urgency=low
    
      * In the interest of testing other GSS-API mechanisms it is desirable to
        install the gss-server and gss-client application. These are useful to
        people developing new GSS-API mechanisms within Debian.
     -- Chuck Short <email address hidden>   Sat, 04 Jun 2011 07:43:48 +0100