LWN.net Logo

Fedora alert FEDORA-2011-17492 (krb5-appl)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 15 Update: krb5-appl-1.0.1-8.fc15
Date:  Thu, 05 Jan 2012 20:57:26 +0000
Message-ID:  <20120105205726.684542130B@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2011-17492 2011-12-27 22:20:34 -------------------------------------------------------------------------------- Name : krb5-appl Product : Fedora 15 Version : 1.0.1 Release : 8.fc15 URL : http://web.mit.edu/kerberos/www/ Summary : Kerberos-aware versions of telnet, ftp, rsh, and rlogin Description : This package contains Kerberos-aware versions of the telnet, ftp, rcp, rsh, and rlogin clients and servers. While these have been replaced by tools such as OpenSSH in most environments, they remain in use in others. -------------------------------------------------------------------------------- Update Information: This update incorporates the upstream patch to fix a buffer overflow in the Kerberos-aware telnet server. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 27 2011 Nalin Dahyabhai <nalin@redhat.com> - 1.0.1-8 - add upstream patch for telnetd buffer overflow (CVE-2011-4862, #770325) * Tue Jul 5 2011 Nalin Dahyabhai <nalin@redhat.com> - 1.0.1-7 - ftpd: add candidate patch to detect setegid/setregid/setresgid and check for errors when calling them (MITKRB5-SA-2011-005, CVE-2011-1526, #713341) -------------------------------------------------------------------------------- References: [ 1 ] Bug #770325 - CVE-2011-4862 krb5: telnet client and server encrypt_keyid heap-based buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=770325 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update krb5-appl' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds