Red Hat Security Advisory: krb5 security, bug fix and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2014-4341 — krb5: denial of service flaws when handling padding length longer than the plaintext CVE-2014-4342 — krb5: denial of service flaws when handling RFC 1964 tokens CVE-2014-4343 — krb5: double-free flaw in SPNEGO initiators CVE-2014-4344 — krb5: NULL pointer dereference flaw in SPNEGO acceptor for continuation tokens CVE-2014-4345 — krb5: buffer overrun in kadmind with LDAP backend (MITKRB5-SA-2014-001) CVE-2014-5352 — krb5: gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001) CVE-2014-5353 — krb5: NULL pointer dereference when using a ticket policy name as a password policy name CVE-2014-9421 — krb5: kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001) CVE-2014-9422 — krb5: kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001) CVE-2014-9423 — krb5: libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001)
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2015:0439
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1084068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1102837
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1109102
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1109919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1116180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1118347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1120581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1121789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1121876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1121877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1127995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1128157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1166012
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1174543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1179856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1179857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1179861
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1179863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1184629
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_0439.json