openSUSE: 2021:3454-1 moderate: krb5
Description
This update for krb5 fixes the following issues: - CVE-2021-37750: Fixed KDC null pointer dereference via a FAST inner body that lacks a server field (bsc#1189929).
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3454=1
Package List
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): krb5-1.16.3-3.24.1 krb5-client-1.16.3-3.24.1 krb5-client-debuginfo-1.16.3-3.24.1 krb5-debuginfo-1.16.3-3.24.1 krb5-debugsource-1.16.3-3.24.1 krb5-devel-1.16.3-3.24.1 krb5-plugin-kdb-ldap-1.16.3-3.24.1 krb5-plugin-kdb-ldap-debuginfo-1.16.3-3.24.1 krb5-plugin-preauth-otp-1.16.3-3.24.1 krb5-plugin-preauth-otp-debuginfo-1.16.3-3.24.1 krb5-plugin-preauth-pkinit-1.16.3-3.24.1 krb5-plugin-preauth-pkinit-debuginfo-1.16.3-3.24.1 krb5-server-1.16.3-3.24.1 krb5-server-debuginfo-1.16.3-3.24.1 - openSUSE Leap 15.3 (x86_64): krb5-32bit-1.16.3-3.24.1 krb5-32bit-debuginfo-1.16.3-3.24.1 krb5-devel-32bit-1.16.3-3.24.1
References
https://www.suse.com/security/cve/CVE-2021-37750.html https://bugzilla.suse.com/1189929