-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 3 Apr 2007 15:53:47 -0700 Source: krb5 Binary: krb5-doc libkrb5-dev krb5-rsh-server krb5-user krb5-ftpd libkadm55 libkrb53 krb5-clients krb5-telnetd krb5-kdc krb5-admin-server Architecture: i386 all Version: 1.3.6-4ubuntu0.2 Distribution: breezy-security Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Kees Cook Description: krb5-admin-server - MIT Kerberos master server (kadmind) krb5-clients - Secure replacements for ftp, telnet and rsh using MIT Kerberos krb5-doc - Documentation for krb5 krb5-ftpd - Secure FTP server supporting MIT Kerberos krb5-kdc - MIT Kerberos key server (KDC) krb5-rsh-server - Secure replacements for rshd and rlogind using MIT Kerberos krb5-telnetd - Secure telnet server supporting MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libkadm55 - MIT Kerberos administration runtime libraries libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - MIT Kerberos runtime libraries Changes: krb5 (1.3.6-4ubuntu0.2) breezy-security; urgency=low . * SECURITY UPDATE: arbitrary login via telnet, arbitrary code execution via syslog buffer overflows, and heap corruption via GSS api. * src/appl/telnet/telnetd/{state,sys_term}.c: MIT-SA-2007-1 fix from upstream (CVE-2007-0956). * src/lib/kadm5/logger.c: MIT-SA-2007-2 fix from Debian, based on upstream fixes (CVE-2007-0957). * src/lib/gssapi/krb5/k5unseal.c: MIT-SA-2007-3 fix from upstream (CVE-2007-1216). * References http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt Files: bb72ee539ddf1e1c4695604ec4a0f9e5 826204 doc optional krb5-doc_1.3.6-4ubuntu0.2_all.deb 1e9111b503cb504a274f7015d6688140 157134 libs optional libkadm55_1.3.6-4ubuntu0.2_i386.deb d35fd02fea44c1cdf67ec0482066b49d 329164 libs standard libkrb53_1.3.6-4ubuntu0.2_i386.deb 5a34afdb0f12a97760952ed5ec124260 126540 net optional krb5-user_1.3.6-4ubuntu0.2_i386.deb 1884960f9dd261886e38cd8265389441 187746 net optional krb5-clients_1.3.6-4ubuntu0.2_i386.deb 02045512c5452976362ccb1c7f99c427 73714 net optional krb5-rsh-server_1.3.6-4ubuntu0.2_i386.deb 3fbdc516bcd61a6003d61952ca4cff3e 52160 net extra krb5-ftpd_1.3.6-4ubuntu0.2_i386.deb c237bdcae4d27193eae17b5c562428a7 56878 net extra krb5-telnetd_1.3.6-4ubuntu0.2_i386.deb f336adcf9b28a00bcd94a81e9e6adb20 117778 net optional krb5-kdc_1.3.6-4ubuntu0.2_i386.deb 1fd24ea021d252e3e1e19d6cdfd897d4 95780 net optional krb5-admin-server_1.3.6-4ubuntu0.2_i386.deb bc93879857377b388e3b393aa20cf26a 540544 libdevel extra libkrb5-dev_1.3.6-4ubuntu0.2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFGEuEc0N0xjzyQZEIRAoFpAJ9vEF+CdLiDuDCj8Yomwn8ObHGZcQCePvAS PUe2zHc0kjzuL0VuLTwxigo= =mDh1 -----END PGP SIGNATURE-----