Oval Definition:oval:org.mitre.oval:def:22765
Revision Date:2014-05-26Version:24
Title:ELSA-2009:0408: krb5 security update (Important)
Description:The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0844
CVE-2009-0845
CVE-2009-0846
ELSA-2009:0408-01
Platform(s):Oracle Linux 5
Product(s):krb5
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • krb5-libs is earlier than 0:1.6.1-31.el5_3.3
  • OR krb5-devel is earlier than 0:1.6.1-31.el5_3.3
  • OR krb5-server is earlier than 0:1.6.1-31.el5_3.3
  • OR krb5 is earlier than 0:1.6.1-31.el5_3.3
  • OR krb5-workstation is earlier than 0:1.6.1-31.el5_3.3
  • BACK