ELSA-2008-0180

ELSA-2008-0180 - Critical: krb5 security update

Type:SECURITY
Severity:CRITICAL
Release Date:2008-03-18

Description


[1.3.4-54.el4_6.1]
- add preliminary patch to fix use of uninitialized pointer / double-free in
KDC (CVE-2008-0062,CVE-2008-0063) (#432620, #432621)
- add backported patch to fix double-free in libgssapi_krb5 (CVE-2007-5971)
(#415351)


Related CVEs


CVE-2007-5971
CVE-2008-0062
CVE-2008-0063

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) krb5-1.3.4-54.el4_6.1.src.rpm84c5f4a27ea3eb7382f53197755f585cELSA-2011-1851
krb5-devel-1.3.4-54.el4_6.1.i386.rpmcf44ced68d63205296afc2ad9e898f9cELSA-2011-1851
krb5-libs-1.3.4-54.el4_6.1.i386.rpm9d56e401df1be51103e3678fc1448147ELSA-2011-1851
krb5-server-1.3.4-54.el4_6.1.i386.rpm910abf05708e2a4de68e52201f00a36eELSA-2011-1851
krb5-workstation-1.3.4-54.el4_6.1.i386.rpmee172694abc0b0ed93fc9c0d7011412bELSA-2011-1851
Oracle Linux 4 (ia64) krb5-1.3.4-54.el4_6.1.src.rpm84c5f4a27ea3eb7382f53197755f585cELSA-2011-1851
krb5-devel-1.3.4-54.el4_6.1.ia64.rpm39e80c84a41b25841b22387d2e084c30ELSA-2011-1851
krb5-libs-1.3.4-54.el4_6.1.i386.rpm9d56e401df1be51103e3678fc1448147ELSA-2011-1851
krb5-libs-1.3.4-54.el4_6.1.ia64.rpme2ba43de5ce6d9c3a7ddb5112728cdcdELSA-2011-1851
krb5-server-1.3.4-54.el4_6.1.ia64.rpme5b36ae1024203c6c3b5642b2b9a7f91ELSA-2011-1851
krb5-workstation-1.3.4-54.el4_6.1.ia64.rpmc980d97b3f27de6f81c2e8ff7e0bdcf9ELSA-2011-1851
Oracle Linux 4 (x86_64) krb5-1.3.4-54.el4_6.1.src.rpm84c5f4a27ea3eb7382f53197755f585cELSA-2011-1851
krb5-devel-1.3.4-54.el4_6.1.x86_64.rpm9f77b8e6f2967e5eec3bc97ca708557aELSA-2011-1851
krb5-libs-1.3.4-54.el4_6.1.i386.rpm9d56e401df1be51103e3678fc1448147ELSA-2011-1851
krb5-libs-1.3.4-54.el4_6.1.x86_64.rpmd4d1371ae191eab68ebb653cf9ac0202ELSA-2011-1851
krb5-server-1.3.4-54.el4_6.1.x86_64.rpm61ddbe65f2a06a97542fa71874d7f7b6ELSA-2011-1851
krb5-workstation-1.3.4-54.el4_6.1.x86_64.rpm4e33397399ae25109bc84181892b9450ELSA-2011-1851



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete