ELSA-2022-8640

ELSA-2022-8640 - krb5 security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2022-11-29

Description


[1.15.1-55.0.1]
- Add recursion limit for ASN.1 indefinite lengths [Orabug: 32582360]

[1.15.1-55]
- Fix integer overflows in PAC parsing (CVE-2022-42898)
- Resolves: rhbz#2140961


Related CVEs


CVE-2022-42898

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) krb5-1.15.1-55.0.1.el7_9.src.rpm8e249438d080dc1eead2de5861dfe143-
krb5-devel-1.15.1-55.0.1.el7_9.aarch64.rpmbfcb2d243bf10c24760383d31f80ae25-
krb5-libs-1.15.1-55.0.1.el7_9.aarch64.rpm38cc83f399d845fcb3fd7b6a25909767-
krb5-pkinit-1.15.1-55.0.1.el7_9.aarch64.rpm443bfe2b23505614103d6bebe896d65b-
krb5-server-1.15.1-55.0.1.el7_9.aarch64.rpm46f39cfc2129ca647389c45fea11eceb-
krb5-server-ldap-1.15.1-55.0.1.el7_9.aarch64.rpmf5fe32195ab42ab4222e7df3743cc5c3-
krb5-workstation-1.15.1-55.0.1.el7_9.aarch64.rpm907f91cf9f663900136aa1d12a30630a-
libkadm5-1.15.1-55.0.1.el7_9.aarch64.rpm6c575f8c99d5aa24bc25187977f8a01b-
Oracle Linux 7 (x86_64) krb5-1.15.1-55.0.1.el7_9.src.rpm8e249438d080dc1eead2de5861dfe143-
krb5-devel-1.15.1-55.0.1.el7_9.i686.rpmd85807f299d0802c182d43ff570e99c5-
krb5-devel-1.15.1-55.0.1.el7_9.x86_64.rpm2923d4d58c89fa0f3951f879c4d9dff0-
krb5-libs-1.15.1-55.0.1.el7_9.i686.rpm2674afe4a3d0632222bae30ac2148204-
krb5-libs-1.15.1-55.0.1.el7_9.x86_64.rpm7675e6659c3002107d305ba88ee1588a-
krb5-pkinit-1.15.1-55.0.1.el7_9.x86_64.rpm2c0c43821599a43ecf7e4a6e6e9b8753-
krb5-server-1.15.1-55.0.1.el7_9.x86_64.rpm6650cef826a7470dd2859ed6588e98a6-
krb5-server-ldap-1.15.1-55.0.1.el7_9.x86_64.rpm1b5bbaedcc76a51b5d644d11b5910f60-
krb5-workstation-1.15.1-55.0.1.el7_9.x86_64.rpm8b5e0d789a611dffa469b35abf5575df-
libkadm5-1.15.1-55.0.1.el7_9.i686.rpm04bb7db66bcf05d4f01476f4a2e5e094-
libkadm5-1.15.1-55.0.1.el7_9.x86_64.rpm69718581f01fe0f8566f765e29ba90d4-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete