Oval Definition:oval:org.opensuse.security:def:80027
Revision Date:2015-02-06Version:1
Title:Security update for krb5
Description:



krb5 has been updated to fix four security issues:

* CVE-2014-5352: gss_process_context_token() incorrectly frees context (bsc#912002) * CVE-2014-9421: kadmind doubly frees partial deserialization results (bsc#912002) * CVE-2014-9422: kadmind incorrectly validates server principal name (bsc#912002) * CVE-2014-9423: libgssrpc server applications leak uninitialized bytes (bsc#912002)

Additionally, these non-security issues have been fixed:

* Winbind process hangs indefinitely without DC. (bsc#872912) * Hanging winbind processes. (bsc#906557)

Security Issues:

* CVE-2014-5352 * CVE-2014-9421 * CVE-2014-9422 * CVE-2014-9423

Family:unixClass:patch
Status:Reference(s):872912
906557
912002
CVE-2014-5352
CVE-2014-9421
CVE-2014-9422
CVE-2014-9423
SUSE-SU-2015:0257-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP3
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • krb5-1.6.3-133.49.66.1 is installed
  • OR krb5-32bit-1.6.3-133.49.66.1 is installed
  • OR krb5-client-1.6.3-133.49.66.1 is installed
  • BACK