ELSA-2009-0408

ELSA-2009-0408 - krb5 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2009-04-07

Description



[1.6.1-31.el5_3.3]
- update to revised patch for CVE-2009-0844/CVE-2009-0845

[1.6.1-31.el5_3.2]
- add fix for potential buffer read overrun in the SPNEGO GSSAPI mechanism
(#490635, CVE-2009-0844)
- add fix for NULL pointer dereference when handling certain error cases
in the SPNEGO GSSAPI mechanism (#490635, CVE-2009-0845)
- add fix for attempt to free uninitialized pointer in the ASN.1 decoder
(#490635, CVE-2009-0846)
- add fix for bug in length validation in the ASN.1 decoder (CVE-2009-0847)

[1.6.1-31.el5_3.1]
- add backport of svn patch to fix a bug in how the gssapi library
handles certain error cases in gss_accept_sec_context (CVE-2009-0845,


Related CVEs


CVE-2009-0846
CVE-2009-0845
CVE-2009-0844

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 5 (i386) krb5-1.6.1-31.el5_3.3.src.rpm65a132db451368a44cfed04372f39453bb1c4f4cb7944a41f1aa2944737cd88aELSA-2014-1255el5_u3_i386_patch
krb5-devel-1.6.1-31.el5_3.3.i386.rpm84f261750a1402e71ebf4d0ce0c17b655357ee980e5a3c00368839ba10ff93dcELSA-2014-1255el5_u3_i386_patch
krb5-libs-1.6.1-31.el5_3.3.i386.rpm1cf58de0a34a00f648b3176894863868b2d26537eb81bdb3a79ed31bc8a2e205ELSA-2014-1255el5_u3_i386_patch
krb5-server-1.6.1-31.el5_3.3.i386.rpm104330fddd8e8cc1e39d5dab1c47baa164d5503283b31bf3edb9aa66eb1b93e0ELSA-2014-1255el5_u3_i386_patch
krb5-workstation-1.6.1-31.el5_3.3.i386.rpme55e180b1db7022c444f1795a33972a1eb5725841a15554c3f5c49f66aadefa0ELSA-2014-1255el5_u3_i386_patch
Oracle Linux 5 (x86_64) krb5-1.6.1-31.el5_3.3.src.rpm65a132db451368a44cfed04372f39453bb1c4f4cb7944a41f1aa2944737cd88aELSA-2014-1255el5_u3_x86_64_patch
krb5-devel-1.6.1-31.el5_3.3.i386.rpm84f261750a1402e71ebf4d0ce0c17b655357ee980e5a3c00368839ba10ff93dcELSA-2014-1255el5_u3_x86_64_patch
krb5-devel-1.6.1-31.el5_3.3.x86_64.rpm3f7219fcdf0a822704cc0d5689209755388793179ce324f992693d3a1f8f9bdbELSA-2014-1255el5_u3_x86_64_patch
krb5-libs-1.6.1-31.el5_3.3.i386.rpm1cf58de0a34a00f648b3176894863868b2d26537eb81bdb3a79ed31bc8a2e205ELSA-2014-1255el5_u3_x86_64_patch
krb5-libs-1.6.1-31.el5_3.3.x86_64.rpm3a292fb35e30e2d196b9e5511e1db48f39765a0cebf0e00167004cea0f953348ELSA-2014-1255el5_u3_x86_64_patch
krb5-server-1.6.1-31.el5_3.3.x86_64.rpmb81baeff8b5f17b4dc4bf409efc1286f74925c201e0ba390056f6c78de463fa9ELSA-2014-1255el5_u3_x86_64_patch
krb5-workstation-1.6.1-31.el5_3.3.x86_64.rpm17a57072740f5f4660f3d1733ec56379a266e62398ad7b589daff116e467a43bELSA-2014-1255el5_u3_x86_64_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete