New Debian krb5 1.20.1-2+deb12u3 fixes: This update addresses the following issues: 1.20.1-2+deb12u3 (Sun, 23 Feb 2025 17:42:24 +0000) * Non Maintainer upload by LTS team * Fixes CVE-2024-26462 A memory leak vulnerability was found in /krb5/src/kdc/ndr.c. * Fixes CVE-2025-24528 Prevent overflow when calculating ulog block size * Add Salsa CI
--- mirror/ftp/pool/main/k/krb5/krb5_1.20.1-2+deb12u2.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/krb5_1.20.1-2+deb12u3.dsc @@ -1,5 +1,14 @@ +1.20.1-2+deb12u3 [Sun, 23 Feb 2025 17:42:24 +0000] Bastien Roucariès <rouca@debian.org>: + + * Non Maintainer upload by LTS team + * Fixes CVE-2024-26462 (Closes: #1064965) + A memory leak vulnerability was found in /krb5/src/kdc/ndr.c. + * Fixes CVE-2025-24528 (Closes: #1094730) + Prevent overflow when calculating ulog block size + * Add Salsa CI + 1.20.1-2+deb12u2 [Mon, 01 Jul 2024 11:31:35 -0600] Sam Hartman <hartmans@debian.org>: - + * CVE-2024-37370: an unauthenticated attacker can modify the extra count in an RFC 4121 GSS token, causing the token to appear truncated. <http://piuparts.knut.univention.de/5.2-1/#517969669078056357>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] 9797b4bd3dc Bug #58281: krb5 1.20.1-2+deb12u3 doc/errata/staging/krb5.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x94>