Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2015:1898-1 Critical Update: KRB5 Process Crash Security Fix

suse
Calendar Grey November 4, 2015
Dist Suse Esm H88
SUSE Patch Notification addressing krb5 severe issue resolution, advisory ID: SUSE-PN-2023:4321-1. Discover further details.
An update that fixes one vulnerability is now available

Summary

krb5 was updated to fix one security issue. This security issue was fixed: - CVE-2015-2695: Applications which call gss_inquire_context() on a partially-established SPNEGO context could have caused the GSS-API library to read from a pointer using the wrong type, generally causing a process crash (bsc#952188). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-krb5-12185=1 - SUSE Linux Enterprise Software Development Kit 11-SP3: zypper in -t patch sdksp3-krb5-12185=1 - SUSE Linux Enterprise Server for VMWare 11-SP3: zypper in -t patch slessp3-krb5-12185=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-krb5-12185=1

References

#952188

Cross- CVE-2015-2695

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Software Development Kit 11-SP3

SUSE Linux Enterprise Server for VMWare 11-SP3

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Desktop 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-2695.html

https://bugzilla.suse.com/show_bug.cgi?id=952188

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1898-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here