<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
<generator>
<oval:product_name>Oracle Errata System</oval:product_name>
<oval:product_version>Oracle Linux</oval:product_version>
<oval:schema_version>5.11</oval:schema_version>
<oval:timestamp>2024-09-21T18:50:12</oval:timestamp>
</generator>
<definitions>
<definition id="oval:com.oracle.elsa:def:20162591" version="501" class="patch">
<metadata>
<title>
ELSA-2016-2591:  krb5 security, bug fix, and enhancement update (LOW)
</title>
<affected family="unix">
<platform>Oracle Linux 7</platform>

</affected>
<reference source="elsa" ref_id="ELSA-2016-2591" ref_url="https://linux.oracle.com/errata/ELSA-2016-2591.html"/>
<reference source="CVE" ref_id="CVE-2016-3120" ref_url="https://linux.oracle.com/cve/CVE-2016-3120.html"/>
<reference source="CVE" ref_id="CVE-2016-3119" ref_url="https://linux.oracle.com/cve/CVE-2016-3119.html"/>

<description>
[1.14.1-26]
- Use responder in non-preauth AS reqs
- Resolves: #1363690

[1.14.1-25]
- Fix bad debug_log() call in selinux handling
- Resolves: #1292153

[1.14.1-24]
- Fix KKDCPP with TLS SNI by always presenting 'Host:' header
- Resolves: #1364993

[1.14.1-23]
- Add dependency on libkadm5 to krb5-devel
- Resolves: #1347403

[1.14.1-22]
- Builders have new version of mock; adapt.
- Resolves: #1290239

[1.14.1-21]
- Fix CVE-2016-3120
- Resolves: #1361504

[1.14.1-20]
- Make version dependencies on libkadm5 more explicit to appease rpmdiff
- Resolves: #1347403

[1.14.1-19]
- Add in upstream version of kprop port and tests
- Resolves: #1292795

[1.14.1-18]
- Fix incorrect recv() size calculation in libkrad
- Resolves: #1349042

[1.14.1-17]
- Separate out the kadm5 libs
- Resolves: #1347403

[1.14.1-16]
- Fix kprop/iprop handling of default realm
- Fix t_kprop.py
- Resolves: #1290561
- Resolves: #1302967
- Resolves: #1292795

[1.14.1-15]
- Fix SPNEGO with NTLM to conform to MS-SPNG section 3.3.5.1
- Resolves: #1341726

[1.14.1-14]
- Do not indicate depricated mechanisms when requested
- Resolves: #1293908

[1.14.1-13]
- Fix OTP module incorrectly overwriting as_key
- Resolves: #1340304

[1.14.1-12]
- Fix CVE-2016-3119 (LDAP NULL dereference)
- Resolves: #1339562

[1.14.1-11]
- Make ksu not ask for password without -n
- Resolves: #1247261

[1.14.1-10]
- Frob kadm5 soname version so that the rebase does not break things
- Resolves: #1292153

[1.14.1-9]
- Revamp selinux patch to not leak memory
- Resolves: #1313457

[1.14.1-8]
- Add snippet support in /etc/krb5.conf.d
- Resolves: #1146945

[1.14.1-7]
- Skip unnecessary mech calls in gss_inquire_cred
- Resolves: #1314493

[1.14.1-6]
- Fix impersonate_name to work with interposers
- Resolves: #1284987

[1.14.1-5]
- Fix change tracking of krb5.conf
- Resolves: #1208243

[1.14.1-4]
- Ensure log files are not world-readable
- Resolves: #1256735

[1.14.1-3]
- Clean up initscript handling in spec file
- Resolves: #1283902
- Resolves: #1183058

[1.14.1-2]
- Backport spec file changes from Fedora
- Resolves: #1290239

[1.14.1-1]
- Rebase to new upstream version 1.14.1
- Remove pax logic
- Resolves: #1292153
- Resolves: #1135427
- Resolves: #1265509
- Resolves: #1265510
- Resolves: #1296241
</description>
<!--
 ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ 
-->
<advisory>
<severity>LOW</severity>
<rights>Copyright 2016 Oracle, Inc.</rights>
<issued date="2016-11-09"/>
<cve cvss2="3.5/AV:N/AC:M/Au:S/C:N/I:N/A:P" href="https://linux.oracle.com/cve/CVE-2016-3120.html" public="20160719">CVE-2016-3120</cve>
<cve cvss2="2.1/AV:N/AC:H/Au:S/C:N/I:N/A:P" href="https://linux.oracle.com/cve/CVE-2016-3119.html" public="20160314">CVE-2016-3119</cve>

<affected_cpe_list>
<cpe>cpe:/a:oracle:linux:7:3:base</cpe>
<cpe>cpe:/a:oracle:linux:7::latest_archive</cpe>
</affected_cpe_list>
</advisory>
</metadata>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591001" comment="Oracle Linux 7 is installed"/>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591002" comment="Oracle Linux arch is x86_64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591003" comment="krb5-devel is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591004" comment="krb5-devel is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591005" comment="krb5-libs is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591006" comment="krb5-libs is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591007" comment="krb5-pkinit is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591008" comment="krb5-pkinit is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591009" comment="krb5-server is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591010" comment="krb5-server is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591011" comment="krb5-server-ldap is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591012" comment="krb5-server-ldap is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591013" comment="krb5-workstation is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591014" comment="krb5-workstation is signed with the Oracle Linux 7 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:20162591015" comment="libkadm5 is earlier than 0:1.14.1-26.el7"/>
<criterion test_ref="oval:com.oracle.elsa:tst:20162591016" comment="libkadm5 is signed with the Oracle Linux 7 key"/>
</criteria>
</criteria>
</criteria>
</criteria>

</definition>
</definitions>
<!--
 ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<tests>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591001"  version="501" comment="Oracle Linux 7 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591001" />
<state state_ref="oval:com.oracle.elsa:ste:20162591002" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591002"  version="501" comment="Oracle Linux arch is x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591001" />
<state state_ref="oval:com.oracle.elsa:ste:20162591003" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591003"  version="501" comment="krb5-devel is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591002" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591004"  version="501" comment="krb5-devel is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591002" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591005"  version="501" comment="krb5-libs is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591003" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591006"  version="501" comment="krb5-libs is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591003" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591007"  version="501" comment="krb5-pkinit is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591004" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591008"  version="501" comment="krb5-pkinit is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591004" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591009"  version="501" comment="krb5-server is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591005" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591010"  version="501" comment="krb5-server is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591005" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591011"  version="501" comment="krb5-server-ldap is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591006" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591012"  version="501" comment="krb5-server-ldap is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591006" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591013"  version="501" comment="krb5-workstation is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591007" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591014"  version="501" comment="krb5-workstation is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591007" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591015"  version="501" comment="libkadm5 is earlier than 0:1.14.1-26.el7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591008" />
<state state_ref="oval:com.oracle.elsa:ste:20162591004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:20162591016"  version="501" comment="libkadm5 is signed with the Oracle Linux 7 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:20162591008" />
<state state_ref="oval:com.oracle.elsa:ste:20162591001" />
</rpminfo_test>

</tests>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ 
-->
<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591002" version="501">
<name>krb5-devel</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591001" version="501">
<name>oraclelinux-release</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591004" version="501">
<name>krb5-pkinit</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591003" version="501">
<name>krb5-libs</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591008" version="501">
<name>libkadm5</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591007" version="501">
<name>krb5-workstation</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591006" version="501">
<name>krb5-server-ldap</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:20162591005" version="501">
<name>krb5-server</name>
</rpminfo_object>

</objects>
<states>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20162591001" version="501">
<signature_keyid operation="equals">72f97b74ec551f03</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20162591002" version="501">
<version operation="pattern match">^7</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20162591003" version="501">
<arch operation="pattern match">x86_64</arch>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:20162591004" version="501">
<evr datatype="evr_string" operation="less than">0:1.14.1-26.el7</evr>
</rpminfo_state>

</states>
</oval_definitions>
