krb5 1.8.1+dfsg-2ubuntu0.13 source package in Ubuntu

Changelog

krb5 (1.8.1+dfsg-2ubuntu0.13) lucid-security; urgency=medium

  * SECURITY UPDATE: denial of service via malformed KRB5_PADATA_PK_AS_REQ
    AS-REQ request
    - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c: don't dereference
      null pointer.
    - c773d3c775e9b2d88bcdff5f8a8ba88d7ec4e8ed
    - CVE-2013-1415
  * SECURITY UPDATE: denial of service via crafted TGS-REQ request
    - src/kdc/do_tgs_req.c: don't pass null pointer to strlcpy().
    - 8ee70ec63931d1e38567905387ab9b1d45734d81
    - CVE-2013-1416
  * SECURITY UPDATE: multi-realm denial of service via crafted request
    - src/kdc/main.c: don't dereference a null pointer.
    - c2ccf4197f697c4ff143b8a786acdd875e70a89d
    - CVE-2013-1418
    - CVE-2013-6800
  * SECURITY UPDATE: denial of service via invalid tokens
    - src/lib/gssapi/krb5/k5unseal.c, src/lib/gssapi/krb5/k5unsealiov.c:
      handle invalid tokens.
    - fb99962cbd063ac04c9a9d2cc7c75eab73f3533d
    - CVE-2014-4341
    - CVE-2014-4342
  * SECURITY UPDATE: denial of service via double-free in SPNEGO
    - src/lib/gssapi/spnego/spnego_mech.c: fix double-free.
    - f18ddf5d82de0ab7591a36e465bc24225776940f
    - CVE-2014-4343
  * SECURITY UPDATE: denial of service via null deref in SPNEGO acceptor
    - src/lib/gssapi/spnego/spnego_mech.c: validate REMAIN.
    - 524688ce87a15fc75f87efc8c039ba4c7d5c197b
    - CVE-2014-4344
  * SECURITY UPDATE: denial of service and possible code execution in
    kadmind with LDAP backend
    - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c: fix off-by-one
    - 81c332e29f10887c6b9deb065f81ba259f4c7e03
    - CVE-2014-4345
 -- Marc Deslauriers <email address hidden>   Fri, 08 Aug 2014 15:03:17 -0400

Upload details

Uploaded by:
Marc Deslauriers on 2014-08-08
Uploaded to:
Lucid
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
krb5_1.8.1+dfsg.orig.tar.gz 11.1 MiB 122cd1358367937ed38bb3a7a8d26601b637b8906cfdf0eacad78f61b4412d8d
krb5_1.8.1+dfsg-2ubuntu0.13.diff.gz 135.7 KiB d7e171c9a9c21ed61655035feca46f32fb1cc402270946d46e1b566a39a474dc
krb5_1.8.1+dfsg-2ubuntu0.13.dsc 2.3 KiB d1c69f0e4e0f8628be204fc8fbba30a6823aa9e26b664076701c8d50f061ec47

View changes file

Binary packages built by this source

krb5-admin-server: No summary available for krb5-admin-server in ubuntu lucid.

No description available for krb5-admin-server in ubuntu lucid.

krb5-doc: No summary available for krb5-doc in ubuntu lucid.

No description available for krb5-doc in ubuntu lucid.

krb5-kdc: No summary available for krb5-kdc in ubuntu lucid.

No description available for krb5-kdc in ubuntu lucid.

krb5-kdc-ldap: No summary available for krb5-kdc-ldap in ubuntu lucid.

No description available for krb5-kdc-ldap in ubuntu lucid.

krb5-multidev: No summary available for krb5-multidev in ubuntu lucid.

No description available for krb5-multidev in ubuntu lucid.

krb5-pkinit: No summary available for krb5-pkinit in ubuntu lucid.

No description available for krb5-pkinit in ubuntu lucid.

krb5-user: No summary available for krb5-user in ubuntu lucid.

No description available for krb5-user in ubuntu lucid.

libgssapi-krb5-2: No summary available for libgssapi-krb5-2 in ubuntu lucid.

No description available for libgssapi-krb5-2 in ubuntu lucid.

libgssrpc4: No summary available for libgssrpc4 in ubuntu lucid.

No description available for libgssrpc4 in ubuntu lucid.

libk5crypto3: No summary available for libk5crypto3 in ubuntu lucid.

No description available for libk5crypto3 in ubuntu lucid.

libkadm5clnt-mit7: No summary available for libkadm5clnt-mit7 in ubuntu lucid.

No description available for libkadm5clnt-mit7 in ubuntu lucid.

libkadm5srv-mit7: No summary available for libkadm5srv-mit7 in ubuntu lucid.

No description available for libkadm5srv-mit7 in ubuntu lucid.

libkdb5-4: No summary available for libkdb5-4 in ubuntu lucid.

No description available for libkdb5-4 in ubuntu lucid.

libkrb5-3: No summary available for libkrb5-3 in ubuntu lucid.

No description available for libkrb5-3 in ubuntu lucid.

libkrb5-dbg: No summary available for libkrb5-dbg in ubuntu lucid.

No description available for libkrb5-dbg in ubuntu lucid.

libkrb5-dev: No summary available for libkrb5-dev in ubuntu lucid.

No description available for libkrb5-dev in ubuntu lucid.

libkrb5support0: No summary available for libkrb5support0 in ubuntu lucid.

No description available for libkrb5support0 in ubuntu lucid.