* bsc#1189929 Cross-References: * CVE-2021-37750 . # Security update for krb5 Announcement ID: SUSE-SU-2024:1702-1 Rating: moderate References: * bsc#1189929 Cross-References: * CVE-2021-37750 CVSS scores: * CVE-2021-37750 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-37750 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: Fixed inside previous release (v1.16.3-46.3.1): * CVE-2021-37750: Fixed KDC null pointer dereference via a FAST inner body that lacked a server field (bsc#1189929). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1702=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1702=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1702=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1702=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * krb5-debugsource-1.16.3-46.12.1 * krb5-devel-1.16.3-46.12.1 * krb5-debuginfo-1.16.3-46.12.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.12.1 *krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.12.1 * krb5-client-1.16.3-46.12.1 * krb5-debugsource-1.16.3-46.12.1 * krb5-server-debuginfo-1.16.3-46.12.1 * krb5-client-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-1.16.3-46.12.1 * krb5-plugin-preauth-pkinit-1.16.3-46.12.1 * krb5-1.16.3-46.12.1 * krb5-doc-1.16.3-46.12.1 * krb5-plugin-preauth-otp-1.16.3-46.12.1 * krb5-server-1.16.3-46.12.1 * krb5-debuginfo-1.16.3-46.12.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * krb5-32bit-1.16.3-46.12.1 * krb5-debuginfo-32bit-1.16.3-46.12.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.12.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.12.1 * krb5-client-1.16.3-46.12.1 * krb5-debugsource-1.16.3-46.12.1 * krb5-server-debuginfo-1.16.3-46.12.1 * krb5-client-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-1.16.3-46.12.1 * krb5-plugin-preauth-pkinit-1.16.3-46.12.1 * krb5-1.16.3-46.12.1 * krb5-doc-1.16.3-46.12.1 * krb5-plugin-preauth-otp-1.16.3-46.12.1 * krb5-server-1.16.3-46.12.1 * krb5-debuginfo-1.16.3-46.12.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * krb5-32bit-1.16.3-46.12.1 * krb5-debuginfo-32bit-1.16.3-46.12.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.12.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.12.1 * krb5-client-1.16.3-46.12.1 * krb5-debugsource-1.16.3-46.12.1 * krb5-server-debuginfo-1.16.3-46.12.1 * krb5-client-debuginfo-1.16.3-46.12.1 * krb5-plugin-kdb-ldap-1.16.3-46.12.1 * krb5-plugin-preauth-pkinit-1.16.3-46.12.1 * krb5-1.16.3-46.12.1 * krb5-doc-1.16.3-46.12.1 * krb5-plugin-preauth-otp-1.16.3-46.12.1 * krb5-server-1.16.3-46.12.1 *krb5-debuginfo-1.16.3-46.12.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * krb5-32bit-1.16.3-46.12.1 * krb5-debuginfo-32bit-1.16.3-46.12.1 ## References: * https://www.suse.com/security/cve/CVE-2021-37750.html * https://bugzilla.suse.com/show_bug.cgi?id=1189929 . Addressing the krb5 KDC invalid memory access issue referenced in CVE-2021-37750 on SUSE platforms.. SUSE Updates, Krb5 Security, KDC Vulnerability, Open Source Patch, Security Best Practices. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-3576 https://linux.oracle.com/errata/ELSA-2021-3576.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: krb5-devel-1.18.2-8.3.el8_4.i686.rpm krb5-devel-1.18.2-8.3.el8_4.x86_64.rpm krb5-libs-1.18.2-8.3.el8_4.i686.rpm krb5-libs-1.18.2-8.3.el8_4.x86_64.rpm krb5-pkinit-1.18.2-8.3.el8_4.i686.rpm krb5-pkinit-1.18.2-8.3.el8_4.x86_64.rpm krb5-server-1.18.2-8.3.el8_4.i686.rpm krb5-server-1.18.2-8.3.el8_4.x86_64.rpm krb5-server-ldap-1.18.2-8.3.el8_4.i686.rpm krb5-server-ldap-1.18.2-8.3.el8_4.x86_64.rpm krb5-workstation-1.18.2-8.3.el8_4.x86_64.rpm libkadm5-1.18.2-8.3.el8_4.i686.rpm libkadm5-1.18.2-8.3.el8_4.x86_64.rpm aarch64: krb5-devel-1.18.2-8.3.el8_4.aarch64.rpm krb5-libs-1.18.2-8.3.el8_4.aarch64.rpm krb5-pkinit-1.18.2-8.3.el8_4.aarch64.rpm krb5-server-1.18.2-8.3.el8_4.aarch64.rpm krb5-server-ldap-1.18.2-8.3.el8_4.aarch64.rpm krb5-workstation-1.18.2-8.3.el8_4.aarch64.rpm libkadm5-1.18.2-8.3.el8_4.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/krb5-1.18.2-8.3.el8_4.src.rpm Related CVEs: CVE-2021-36222 CVE-2021-37750 Description of changes: [1.18.2-8.3] - Fix KDC null deref on TGS inner body null server (CVE-2021-37750) - Resolves: #1997600 [1.18.2-8.2] - Rebuild for rpminspect; no code changes - Resolves: #1983728 [1.18.2-8.1] - Fix KDC null deref on bad encrypted challenge (CVE-2021-36222) - Resolves: #1983728 _______________________________________________ El-errata mailing list
This update incorporates fixes for a stack buffer overflow and heap corruption in the RPC library, and a fix for a potential stack buffer overflow in kadmind.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-620 2007-06-28 ---------------------------------------------------------------------Product : Fedora Core 5 Name : krb5 Version : 1.4.3 Release : 5.5 Summary : The Kerberos network authentication system. Description : Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure practice of cleartext passwords. ---------------------------------------------------------------------Update Information: This update incorporates fixes for a stack buffer overflow and heap corruption in the RPC library, and a fix for a potential stack buffer overflow in kadmind. ---------------------------------------------------------------------* Wed Jun 27 2007 Nalin Dahyabhai 1.4.3-5.5 - incorporate fixes for MITKRB5-SA-2007-004 (CVE-2007-2442,CVE-2007-2443) and MITKRB5-SA-2007-005 (CVE-2007-2798) * Tue Apr 3 2007 Nalin Dahyabhai 1.4.3-5.4 - add patch to correct unauthorized access via krb5-aware telnet daemon (#229782, CVE-2007-0956) - add patch to fix buffer overflow in krb5kdc and kadmind (#231528, CVE-2007-0957) - add patch to fix double-free in kadmind (#231537, CVE-2007-1216) * Tue Jan 9 2007 Nalin Dahyabhai 1.4.3-5.3 - apply patch from Tom Yu to fix MITKRB-SA-2006-002 (CVE-2006-6143) * Fri Aug 18 2006 Nalin Dahyabhai 1.4.3-5.2 - switch to the updated patch for MITKRB-SA-2006-001 * Tue Aug 8 2006 Nalin Dahyabhai 1.4.3-5.1 - apply patch to address MITKRB-SA-2006-001 (CVE-2006-3084) * Fri Apr 14 2006 Stepan Kasal - 1.4.3-5 - Fix formatting typo in kinit.1 (krb5-kinit-man-typo.patch) ---------------------------------------------------------------------This update can be downloaded from: 428f5a1a16f261507e780a7468adcf054534228a SRPMS/krb5-1.4.3-5.5.src.rpm 428f5a1a16f261507e780a7468adcf054534228a noarch/krb5-1.4.3-5.5.src.rpm ae9338cee91736eab3a108b8713d4dce56e1e41e ppc/debug/krb5-debuginfo-1.4.3-5.5.ppc.rpm 7a6a044dbe79c2b1e52bb37493a125c81ec3d61a ppc/krb5-server-1.4.3-5.5.ppc.rpm 28f4db0ea0ee174c3d027b387e2dc1de3743920a ppc/krb5-libs-1.4.3-5.5.ppc.rpm b2b2e49c40a4f2f9896e1968533df905c9bf5a17 ppc/krb5-workstation-1.4.3-5.5.ppc.rpm d5138a1387d0c53555f30b62453c4acc48c3f850 ppc/krb5-devel-1.4.3-5.5.ppc.rpm fb2b5ee96faeb4a32e5ebef492e3951f884be0b7 x86_64/debug/krb5-debuginfo-1.4.3-5.5.x86_64.rpm c38ff027c2fc12e2f5574978d447d3312f46c083 x86_64/krb5-server-1.4.3-5.5.x86_64.rpm ae8e4ccde571e411765b76813df63179cccb14b0 x86_64/krb5-libs-1.4.3-5.5.x86_64.rpm a429a9a7e6bc3716bc3762aed47949aafce2fe93 x86_64/krb5-devel-1.4.3-5.5.x86_64.rpm 4097c5826880d51c689cc2ac9598865d2d963d2e x86_64/krb5-workstation-1.4.3-5.5.x86_64.rpm dbfb9c6daf7737dba40ef46ee83311179664eddd i386/krb5-devel-1.4.3-5.5.i386.rpm b1d93b42f28f0722f758493897ee8036cce1d8ab i386/krb5-server-1.4.3-5.5.i386.rpm 0d7d3f5d147c26f023e16c5c21f45716bfc04ab2 i386/krb5-libs-1.4.3-5.5.i386.rpm 08bb2e80ac94de576b5bc6129c329fed91e215c1 i386/krb5-workstation-1.4.3-5.5.i386.rpm 270cb51345181477d454f97015af76c5b303a25e i386/debug/krb5-debuginfo-1.4.3-5.5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Updated krb5 packages are now available for Red Hat Enterprise Linux 4 to correct a privilege escalation security flaw. This update has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: krb5 security update Advisory ID: RHSA-2006:0612-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0612.html Issue date: 2006-08-08 Updated on: 2006-08-08 Product: Red Hat Enterprise Linux Keywords: setuid CVE Names: CVE-2006-3083 - ---------------------------------------------------------------------1. Summary: Updated krb5 packages are now available for Red Hat Enterprise Linux 4 to correct a privilege escalation security flaw. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: Kerberos is a network authentication system which allows clients and servers to authenticate to each other through use of symmetric encryption and a trusted third party, the KDC. A flaw was found where some bundled Kerberos-aware applications would fail to check the result of the setuid() call. On Linux 2.6 kernels, the setuid() call can fail if certain user limits are hit. A local attacker could manipulate their environment in such a way to get the applications to continue to run as root, potentially leading to an escalation of privileges. (CVE-2006-3083). Users are advised to update to these erratum packages which contain a backported fix to correct this issue. 4. Solution: Before applying thisupdate, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 197818 - CVE-2006-3083 krb5 multiple unsafe setuid usage 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: cea37ecb1360d88c2fdc83f5419babc1 krb5-1.3.4-33.src.rpm i386: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm 77b0759d3fcc4545c27f34d4e300cc16 krb5-devel-1.3.4-33.i386.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm f3daae1ee3b0631b863635c375afe72a krb5-server-1.3.4-33.i386.rpm f6a4726c5d77d16ea2f0713c92f10bae krb5-workstation-1.3.4-33.i386.rpm ia64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm e4d6ec50ae455203023d5e55b0cca4da krb5-debuginfo-1.3.4-33.ia64.rpm 5dc4a77a4b3c4492afa7f74e83d9f5d0 krb5-devel-1.3.4-33.ia64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm b15d34edd402823f6b5d1d1d0f013d8d krb5-libs-1.3.4-33.ia64.rpm ce76f409b19d6824f5d1fdda67c323ef krb5-server-1.3.4-33.ia64.rpm 4ad475560c2723d011b6cf0faf8eca86 krb5-workstation-1.3.4-33.ia64.rpm ppc: c1739675331b5f8d819eac90ad29c222 krb5-debuginfo-1.3.4-33.ppc.rpm 379c91cb057181e02cdfd6092d3f746c krb5-debuginfo-1.3.4-33.ppc64.rpm 2f5cceda4ec3dcb5a0fca0829055f512 krb5-devel-1.3.4-33.ppc.rpm de6fdc9b22ed426ba7542018e9174adb krb5-libs-1.3.4-33.ppc.rpm 8759e9dd51c3614a5259db73e57a26a3 krb5-libs-1.3.4-33.ppc64.rpm 55ebf269ef488d8a281ee28fcb450383 krb5-server-1.3.4-33.ppc.rpm 4015802b89b7d6b92023a3da7787e30d krb5-workstation-1.3.4-33.ppc.rpm s390: e4a005da7af0377354f69308b9a9acef krb5-debuginfo-1.3.4-33.s390.rpm 55995e2d6b79c58dbb85ec2af716fe78 krb5-devel-1.3.4-33.s390.rpm 811ab87d0c59091d4a0de6e748086d5e krb5-libs-1.3.4-33.s390.rpm 3ec54f81728a0a9ae22afcb2855ed732 krb5-server-1.3.4-33.s390.rpm fe5ee4916e5aa24d499a1f8992d1036d krb5-workstation-1.3.4-33.s390.rpm s390x: e4a005da7af0377354f69308b9a9acef krb5-debuginfo-1.3.4-33.s390.rpm 43c2b4a0cf29aca1247d0c1d6ba4e24a krb5-debuginfo-1.3.4-33.s390x.rpm 4883f400df4d8123c70604a430f92647 krb5-devel-1.3.4-33.s390x.rpm 811ab87d0c59091d4a0de6e748086d5e krb5-libs-1.3.4-33.s390.rpm 1e13d025a766bc5ab50ebe3062586ef9 krb5-libs-1.3.4-33.s390x.rpm 7f3303ba3883bf0c5135cd39ed02122c krb5-server-1.3.4-33.s390x.rpm 1441e757a4e8e58ca29e7270a86d28ef krb5-workstation-1.3.4-33.s390x.rpm x86_64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm ae306e728d14d34e3cf20aa9b979dcd9 krb5-debuginfo-1.3.4-33.x86_64.rpm feada102b3dd0995e10f63e7c53ccf65 krb5-devel-1.3.4-33.x86_64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm 368e23d9adef4244a67b2e1951d2b74b krb5-libs-1.3.4-33.x86_64.rpm e0d823bbf3a2cd51b3e918ab8d669355 krb5-server-1.3.4-33.x86_64.rpm e1b4250df40a8d392f011b2c89f79966 krb5-workstation-1.3.4-33.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: cea37ecb1360d88c2fdc83f5419babc1 krb5-1.3.4-33.src.rpm i386: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm 77b0759d3fcc4545c27f34d4e300cc16 krb5-devel-1.3.4-33.i386.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm f3daae1ee3b0631b863635c375afe72a krb5-server-1.3.4-33.i386.rpm f6a4726c5d77d16ea2f0713c92f10bae krb5-workstation-1.3.4-33.i386.rpm x86_64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm ae306e728d14d34e3cf20aa9b979dcd9 krb5-debuginfo-1.3.4-33.x86_64.rpm feada102b3dd0995e10f63e7c53ccf65 krb5-devel-1.3.4-33.x86_64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm 368e23d9adef4244a67b2e1951d2b74b krb5-libs-1.3.4-33.x86_64.rpm e0d823bbf3a2cd51b3e918ab8d669355 krb5-server-1.3.4-33.x86_64.rpm e1b4250df40a8d392f011b2c89f79966 krb5-workstation-1.3.4-33.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: cea37ecb1360d88c2fdc83f5419babc1 krb5-1.3.4-33.src.rpm i386: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm 77b0759d3fcc4545c27f34d4e300cc16 krb5-devel-1.3.4-33.i386.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm f3daae1ee3b0631b863635c375afe72a krb5-server-1.3.4-33.i386.rpm f6a4726c5d77d16ea2f0713c92f10bae krb5-workstation-1.3.4-33.i386.rpm ia64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm e4d6ec50ae455203023d5e55b0cca4da krb5-debuginfo-1.3.4-33.ia64.rpm 5dc4a77a4b3c4492afa7f74e83d9f5d0 krb5-devel-1.3.4-33.ia64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm b15d34edd402823f6b5d1d1d0f013d8d krb5-libs-1.3.4-33.ia64.rpm ce76f409b19d6824f5d1fdda67c323ef krb5-server-1.3.4-33.ia64.rpm 4ad475560c2723d011b6cf0faf8eca86 krb5-workstation-1.3.4-33.ia64.rpm x86_64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm ae306e728d14d34e3cf20aa9b979dcd9 krb5-debuginfo-1.3.4-33.x86_64.rpm feada102b3dd0995e10f63e7c53ccf65 krb5-devel-1.3.4-33.x86_64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm 368e23d9adef4244a67b2e1951d2b74b krb5-libs-1.3.4-33.x86_64.rpm e0d823bbf3a2cd51b3e918ab8d669355 krb5-server-1.3.4-33.x86_64.rpm e1b4250df40a8d392f011b2c89f79966 krb5-workstation-1.3.4-33.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: cea37ecb1360d88c2fdc83f5419babc1 krb5-1.3.4-33.src.rpm i386: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm 77b0759d3fcc4545c27f34d4e300cc16 krb5-devel-1.3.4-33.i386.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm f3daae1ee3b0631b863635c375afe72a krb5-server-1.3.4-33.i386.rpm f6a4726c5d77d16ea2f0713c92f10bae krb5-workstation-1.3.4-33.i386.rpm ia64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm e4d6ec50ae455203023d5e55b0cca4da krb5-debuginfo-1.3.4-33.ia64.rpm 5dc4a77a4b3c4492afa7f74e83d9f5d0 krb5-devel-1.3.4-33.ia64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm b15d34edd402823f6b5d1d1d0f013d8d krb5-libs-1.3.4-33.ia64.rpm ce76f409b19d6824f5d1fdda67c323ef krb5-server-1.3.4-33.ia64.rpm 4ad475560c2723d011b6cf0faf8eca86 krb5-workstation-1.3.4-33.ia64.rpm x86_64: 7a3e83832f13a55c39a1ccc079a5c556 krb5-debuginfo-1.3.4-33.i386.rpm ae306e728d14d34e3cf20aa9b979dcd9 krb5-debuginfo-1.3.4-33.x86_64.rpm feada102b3dd0995e10f63e7c53ccf65 krb5-devel-1.3.4-33.x86_64.rpm 7650a2f59eb97b17b141804e28f09d44 krb5-libs-1.3.4-33.i386.rpm 368e23d9adef4244a67b2e1951d2b74b krb5-libs-1.3.4-33.x86_64.rpm e0d823bbf3a2cd51b3e918ab8d669355 krb5-server-1.3.4-33.x86_64.rpm e1b4250df40a8d392f011b2c89f79966 krb5-workstation-1.3.4-33.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-3083 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2006 Red Hat, Inc. . Essential krb5 security patch for Red Hat Enterprise Linux swiftly resolves elevation of privilege vulnerability.. krb5 Update, Red Hat Security, Privilege Escalation Fix, Enterprise Linux Packages. . Severity: Important. LinuxSecurity.com Team
Important: php security update. Date: Tue, 12 Jul 2005 18:00:55 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 40 i386 now available Comments: To: scientific The following ERRATA for SL 40 i386 are now available from: Synopsis: Important: krb5 security update Advisory ID: RHSA-2005:567-02 Cross references: RHSA-2005:562 Obsoletes: RHSA-2005:330 CVE Names: CAN-2004-0175 CAN-2005-1174 CAN-2005-1175 CAN-2005-1689 krb5-devel-1.3.4-17.i386.rpm krb5-libs-1.3.4-17.i386.rpm krb5-server-1.3.4-17.i386.rpm krb5-workstation-1.3.4-17.i386.rpm Synopsis: Important: php security update Advisory ID: RHSA-2005:564-01 CVE Names: CAN-2005-1751 CAN-2005-1921 php-4.3.9-3.7.i386.rpm php-devel-4.3.9-3.7.i386.rpm php-domxml-4.3.9-3.7.i386.rpm php-gd-4.3.9-3.7.i386.rpm php-imap-4.3.9-3.7.i386.rpm php-ldap-4.3.9-3.7.i386.rpm php-mbstring-4.3.9-3.7.i386.rpm php-mysql-4.3.9-3.7.i386.rpm php-ncurses-4.3.9-3.7.i386.rpm php-odbc-4.3.9-3.7.i386.rpm php-pear-4.3.9-3.7.i386.rpm php-pgsql-4.3.9-3.7.i386.rpm php-snmp-4.3.9-3.7.i386.rpm php-xmlrpc-4.3.9-3.7.i386.rpm -Connie Sieh . Critical security patch released for python and openssl now ready for Scientific Linux 40 x86_64 users.. PHP Update, Scientific Linux, Security Fix, Krb5 Advisory. . Severity: Important. LinuxSecurity.com Team
A buffer overflow has been discovered in the MIT Kerberos 5 administration library (libkadm5srv) that could lead to the execution of arbitrary code upon exploition by an authenticated user, not necessarily one with administrative privileges.. --------------------------------------------------------------------------Debian Security Advisory DSA 629-1
Get the latest Linux and open source security news straight to your inbox.