This update for libheimdal fixes the following issues:
libheimdal was updated to version 7.7.0:
+ Bug fixes:
- PKCS#11 hcrypto back-end:
+ initialize the p11_module_load function list
+ verify that not only is a mechanism present but that its mechanism
info states that it offers the required encryption, decryption or
digest services
- krb5:
+ Starting with 7.6, Heimdal permitted requesting authenticated
anonymous tickets. However, it did not verify that a KDC in fact
returned an anonymous ticket when one was requested.
+ Cease setting the KDCOption reaquest_anonymous flag when issuing
S4UProxy (constrained delegation) TGS requests.
+ when the Win2K PKINIT compatibility option is set, do not require
krbtgt otherName to match when validating KDC certificate.
+ set PKINIT_BTMM flag per Apple implementation
+ use memset_s() instead of memset()
- kdc:
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1682=1
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2019-1682=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1682=1
- openSUSE Leap 42.3 (i586 x86_64):
libheimdal-7.7.0-12.1
libheimdal-debuginfo-7.7.0-12.1
libheimdal-debugsource-7.7.0-12.1
libheimdal-devel-7.7.0-12.1
- openSUSE Leap 15.1 (x86_64):
libheimdal-7.7.0-lp151.3.3.1
libheimdal-debuginfo-7.7.0-lp151.3.3.1
libheimdal-debugsource-7.7.0-lp151.3.3.1
libheimdal-devel-7.7.0-lp151.3.3.1
- openSUSE Leap 15.0 (x86_64):
libheimdal-7.7.0-lp150.2.3.1
libheimdal-debuginfo-7.7.0-lp150.2.3.1
libheimdal-debugsource-7.7.0-lp150.2.3.1
libheimdal-devel-7.7.0-lp150.2.3.1
https://www.suse.com/security/cve/CVE-2018-16860.html
https://www.suse.com/security/cve/CVE-2019-12098.html
https://bugzilla.suse.com/1047218
https://bugzilla.suse.com/1084909
--
Get the latest Linux and open source security news straight to your inbox.