|
|
Subscribe / Log in / New account

Debian alert DLA-2771-1 (krb5)

From:  Adrian Bunk <bunk@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2771-1] krb5 security update
Date:  Thu, 30 Sep 2021 23:08:58 +0300
Message-ID:  <20210930200858.GA5071@localhost>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2771-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Adrian Bunk September 30, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : krb5 Version : 1.15-1+deb9u3 CVE ID : CVE-2018-5729 CVE-2018-5730 CVE-2018-20217 CVE-2021-37750 Debian Bug : 891869 917387 992607 Several vulnerabilities were fixed in MIT Kerberos, a system for authenticating users and services on a network. CVE-2018-5729 CVE-2018-5730 Fix flaws in LDAP DN checking. CVE-2018-20217 Ignore password attributes for S4U2Self requests. CVE-2021-37750 Fix KDC null deref on TGS inner body null server. For Debian 9 stretch, these problems have been fixed in version 1.15-1+deb9u3. We recommend that you upgrade your krb5 packages. For the detailed security status of krb5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/krb5 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmFWGVoACgkQiNJCh6LY mLEiThAAsZQTq7EOPbbtlMOzT91Totl+DP83/BpJiiza6TUn6DQjs70kCwkfLz/s sAVtb0IZOksoVE3cD4aJXxxmZ/BlMDVUpa8a0Rl6TVDsBnYZP5lPiFluT4mek9dL UKpX8cU2vwe8acAxZt+B5AbnNSolWfzaW/xCX6Vdc8ueuzT5iTkPxQdZ9yhdyPWp FxAZLXO5ju/MiqQqKDp7oMDpFsN7asRzP5KKr+cjMIeAp9dso/htsA6fQZSkjWBf QOn1G9yVAMHCa89zxaKHnEi2R5GjpNICHnWxaxFTpmv9LPw27YOp032FvOoTvnFU um1Yvojm0jtSoTkhsOGJ1EXWyARCcdMTmttcrCtWEzmATSAaD8ERldzFDc9BT1Hm UGAelxfgMDexqa4nyoYTY7O4WotnXPD1nUZQVks+Ar0qRxPAgFBQf37pH4xMmUQJ KxPZRQAqGGqHwXcQnA/MnBu6uw1fL+BGRMVbx+ngsOnrlSB2RejLjLxyxnDUGEV5 kSRQ1ENOrdSYRkY9bp7SergS2HngDl/Bb7UgoosQcJSHUX/XSQzsxAG2Ei08b10n sS61RiNHbmp9PbDrPDMAnB3E7vroayXr8EEovFT2B08vT/i6YKj2BbAv5JhrlwVt BfrQSlJQ5YxUbubltRe7IMERrDeb5BjIvr9TNJx2hBJhbMfMLQA= =hDAP -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds