openSUSE: 2020:2037-1 moderate: krb5
Description
This update for krb5 fixes the following security issue: - CVE-2020-28196: Fixed an unbounded recursion via an ASN.1-encoded Kerberos message (bsc#1178512). This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2037=1
Package List
- openSUSE Leap 15.1 (i586 x86_64): krb5-1.16.3-lp151.2.15.1 krb5-client-1.16.3-lp151.2.15.1 krb5-client-debuginfo-1.16.3-lp151.2.15.1 krb5-debuginfo-1.16.3-lp151.2.15.1 krb5-debugsource-1.16.3-lp151.2.15.1 krb5-devel-1.16.3-lp151.2.15.1 krb5-mini-1.16.3-lp151.2.15.1 krb5-mini-debuginfo-1.16.3-lp151.2.15.1 krb5-mini-debugsource-1.16.3-lp151.2.15.1 krb5-mini-devel-1.16.3-lp151.2.15.1 krb5-plugin-kdb-ldap-1.16.3-lp151.2.15.1 krb5-plugin-kdb-ldap-debuginfo-1.16.3-lp151.2.15.1 krb5-plugin-preauth-otp-1.16.3-lp151.2.15.1 krb5-plugin-preauth-otp-debuginfo-1.16.3-lp151.2.15.1 krb5-plugin-preauth-pkinit-1.16.3-lp151.2.15.1 krb5-plugin-preauth-pkinit-debuginfo-1.16.3-lp151.2.15.1 krb5-server-1.16.3-lp151.2.15.1 krb5-server-debuginfo-1.16.3-lp151.2.15.1 - openSUSE Leap 15.1 (x86_64): krb5-32bit-1.16.3-lp151.2.15.1 krb5-32bit-debuginfo-1.16.3-lp151.2.15.1 krb5-devel-32bit-1.16.3-lp151.2.15.1
References
https://www.suse.com/security/cve/CVE-2020-28196.html https://bugzilla.suse.com/1178512 openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org To unsubscribe, email security-announce-leave@lists.opensuse.org List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette List Archives: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/